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Introduction 


This is a practical handbook on how to make your own codes 
und how to “break” other peoples’ codes. You'll find enough 
theory in this book to give you a good background regarding 
how and why codes work, but the emphasis is on practical topics 
so that you can put this knowledge to work as quickly as 
possible. 


It’s necessary to skim over the history and development of 
codes and ciphers, to place the subject in perspective and to pro- 
vide indications of what’s been tried before. Some efforts failed 
miserably, while others were unqualified successes. Some 
“crypto” efforts affected history. We don’t know about many of 
these efforts because governments are very secretive regarding 
their crypto work. Most of what’s going on today in the many 
cryptographic struggles between governments affects us directly 
and indirectly, but is likely to remain secret during our lifetimes. 


There’s a very definite and solid reason why cryptographic 
secrets are the most closely-guarded, even more than those in- 
volving nuclear weapons. Anyone who manages to steal nuclear 
weapons information has only that. Everything else in the secret 
world is still locked away from him. With the codes and ciphers, 
he has access to all secret communications. This enables 


2 CODE MAKING AND CODE BREAKING 


penetrating the secrecy surrounding many areas. However, the 
areas that governments choose to keep secret may surprise some. 
For example, there’s absolutely no secret about the “unbreak- 
able” code or cipher. These exist, and the technology for pro- 
ducing them has been with us for at least six decades. Many 
governments use unbreakable ciphers. 


Code-breaking, or cryptanalysis, as we shall see, is the most 
secret activity of all. The ability to “read” another country’s traf- 
fic is priceless in many cases, and governments not only jealously 
guard their techniques, but the very fact that they have them. 


Codes have been in use for thousands of years. If there’s a 
need to keep a secret, someone will think of a way to record 
it so that it can’t be read by those not in the know. Some of the 
people who invented codes were naive, and didn’t realize that 
what seemed to be an unbreakable code to them was simple for 
another to crack wide open. At the time, however, most people 
were illiterate, and anything written was incomprehensible to 
them. Those who could read were very unsophisticated regard- 
ing codes and ciphers, and consequently many simple-minded 
ciphers were secure from the opposition. 


Today, with the experience of centuries to guide us, we can 
avoid many common mistakes. We also have some new tech- 
nical aids which were unavailable only a few years ago, and 
which, when properly used, can make codes extremely difficult 
to break. 


Not all codes are equally easy to decipher. The major factor 
in the decision to adopt a particular system is not whether or 
not it’s absolutely unbreakable, but whether the opposition has 
the ability to break it, or whether they can break it in time to 
do them any good. 


The secrecy penetrators in our society have been well-docu- 
mented. Private parties snoop on individuals. Governments 
snoop on individuals and on each other. Organizations, such as 
employers and labor unions, use espionage and various forms of 
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wiretapping and electronic “bugging” to intercept communica- 
tions. Any radio transmission can be overheard. 


If you have a need to keep your communications secret, read 
this book carefully. In these pages you'll find a description of 
inany practical systems for hiding the meanings of your mes- 
sages. You'll find a description and objective appraisal of each 
one, Some are very secure, but hard to use. Others require costly 
equipment, and we won’t waste much time with these. Still 
others are workable if your opponent’s not too bright, but no 
zood against a sophisticated adversary. A few offer good security 
und ease of use. With this array, you should have no problem 
in setting up a code system to meet your needs. This is a nuts- 
und-bolts book, designed to allow the reader to start off with as 
little difficulty as possible. 


This is why many of the exotic ciphers and codes are not in 
this book. We'll discuss briefly various electro-mechanical en- 
cryption machines, but keep in mind that they’re practical only 
lor governments and corporations because of their high cost. 


Some of these beautifully intricate crypto-systems are too 
elaborate and cumbersome to be practical. The mathematical 
“gateing” equations are elegant, but truly impractical for the 
down and dirty conditions in which most of us have to use 
secrecy. Likewise, there are encryption and decryption methods 
adaptable to the home computer, but not everyone has a com- 
puter or the knowledge to use one in a way suitable for crypto- 
yraphy. In any case, this information is available elsewhere. 


There is no glossary of technical terms here. If you’re new to 
the subject, read the chapters in sequence and you'll find the 
technical terms explained as we come to them. It’s better this 
way, because you'll get the definitions in context with the ex- 
planations. 


The bottom line is that it’s much easier to set up a crypto- 
system than to break one. This is why we’ll devote more time 
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and space to discussing codes and ciphers than to explaining 
how to break them. 


Devising a nearly unbreakable code is easy, although not as 
easy as some people think. However, with a little intelligent ef- 
fort, you'll be able to set up your own code or cipher, and make 
it secure enough so that it will be extremely difficult for even 
the most sophisticated code-breaker to unlock. 
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History 


We study history to learn from it. We can draw some valu- 
ble lessons from the cryptographic mistakes of the past. 


We don’t have to examine the history of codes and ciphers 
in nit-picking detail. What’s important is the way that codes and 
ciphers fitted into the needs of their users. The history of 
cryptography is closely intertwined with the history of com- 
inunication, and we'll see that, as means of communication 


increased, so did the need for keeping certain messages secret. 


Codes and ciphers, with one exception, are worthwhile only 
to those who need to keep secrets. This usually means govern- 
ments, because of their diplomatic and military branches, and 
private individuals and organizations engaged in intrigues. The 
reason why military organizations need to keep their secrets is 
obvious. Diplomats often use mis-representations and under-the- 
table deals to further their countries’ ends, and for this reason 
need to keep their communications secret. 


The exception noted above has to do with brevity. In various 
types of transmission and record-keeping, there’s a real need to 
use symbols to save space or time. A conspicuous example of 
this is the group of “telegraph codes” which came about shortly 
after the telegraph became wide-spread. Telegrams are charged 
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by the word, and a commercial code book which uses five or 
six letter code words to represent phrases and even sentences can 
save a company a lot of money in transmission costs. The code 
books are in no way secret, and are available on the open 
market. 


Likewise, the various systems of “short-hand” are codes or 
ciphers, but because anyone can learn them by buying a book 
or taking a class, they’re not secret. They allow a secretary to 
take dictation without having to write every letter or word. 


We also see codes used in radio traffic for the same reason. 
Police channels are crowded, and during peak hours it’s im- 
portant to reduce the length of messages to accommodate the 
large number of users. Thus, “10-28” stands for “check license 
plate number with the Motor Vehicle Department” and “10-29” 
means “check this person or vehicle for outstanding warrants.” 


In ancient times, when practically nobody knew how to read 
or write, messages were verbal. A military commander would 
send a courier, and security of the message depended on the 
courier’s ability to make it safely to his destination. If captured 
by the enemy, he simply had to keep his mouth shut. His captors 
might not even realize that he was a courier, but might assume 
that he was a simple soldier or even a deserter. 


Written messages also depended heavily on the courier’s skill 
for security. Their senders often did not bother to encipher them 
for this reason. Sometimes, they miscalculated. The capture of 
the British courier, Major John Andre, by American forces dur- 
ing the Revolutionary War had serious consequences because of 
the material he was carrying. It led to the exposure of Benedict 
Arnold as a traitor. 


Couriers allowed the sender to direct the message very pre- 
cisely. To intercept the message, it was imperative to intercept 
the courier, and this wasn’t easy to do. The electronic explosion 
changed this drastically. At first, the telegraph was vulnerable to 
anyone who had access to the line. It was impossible to guard 
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every telegraph wire over every foot of its length, and anyone 
with crude equipment could tap into the line and read the 
inessages. Use of the telegraph during the American Civil War 
led to the first widespread use of codes and ciphers in warfare. 


lt wasn’t the first American effort in truly secure crypto-com- 
munication, though. Many years before, the third American 
resident, Thomas Jefferson, invented a ciphering device based 
on polyalphabetical substitution. This was the basic device upon 
which many recent American devices are based, and the 
ilevelopment of this device led to the electro-mechanical cipher 
inachines developed in the years between the two world wars. 


Radio made it worse for the sender, who spread his message 
over a wide area. The eavesdropper didn’t need to touch or even 
come Close to his target’s equipment, but could pick up his mes- 
sages from thousands of miles away under favorable conditions. 
With direction-finding gear, he could estimate the location of the 
transmitter. This was valuable for locating enemy ships. This is 
why a German general said, during World War II, that use of 
the radio was treason. 


The growth of cryptology was also a result of the growth of 
military and “intelligence” services. With larger armies and 
navies, as well as the beginning of a new service, the air force, 
there were more messages to send, and the pressure of time made 
them more urgent. Modern intelligence services, unlike the old 
espionage services, tend to stress technical means of information- 
gathering over human factors. This is because they’ve learned to 
deduce important facts about their enemies from intercepting 
their communications. Direction-finding equipment located 
enemy transmitters. Listing and analyzing the contents of mes- 
sages disclosed information about the location, strength, and 
plans of enemy forces. A request for an ammunition resupply, 
for example, would suggest a coming offensive if it was larger 
than normal. Casualty reports would show how enemy strength 
had declined after a battle. 


a = 
—— 
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With the realization that any scrap of information could help 
an enemy eavesdropper, there arose a system of information 
classification, and a system of codes and ciphers to transmit vari- 
ous types of information. The most secure codes and ciphers 
were for top-secret messages between various military head- 
quarters. Less complex and presumably, less secure, systems 
were for routine administrative traffic and for front-line units 
that might be overrun and their codes captured. 


The very simple “field ciphers” were for small units, and they 
were not very secure. In many cases, pessimistic estimates of 
their difficulty were that a competent code-cracker could undo 
them within hours. This was enough, for by the time a crypt- 
analyst decoded a message, its information would be obsolete. 


Messages of extreme importance, compromise of which 
would be a national disaster, still went by courier. So did de- 
liveries of new crypto-systems. This is still true today. The 
diplomatic pouch is a conduit for codes, cipher machines, and 
related security gear. 


Although a human courier sometimes is still vulnerable to 
capture, sending the message by radio in a possibly insecure 
crypto-system is far worse because an enemy could record and 
de-crypt it without the sender’s knowledge. There have been 
many instances during our century when a government did not 
know that an enemy or rival was reading its most secret mes- 
sages. 


In the following pages we’ll study how certain types of crypto- 
systems fit into various contexts. We'll see how code-breakers 
worked to unlock their secrets, while code-makers scurried to 
create more secure codes and ciphers. 
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Secret Writing: The Basics 


Let’s begin by laying out the difference between a “code” and 
a “cipher.” A code involves using code words, symbols, or 
yroups of numbers to replace words or phrases in the original 
message, or “plaintext.” For example, in a military code book, 
we might find that “GFRDS” stands for “Attack” and 
“HJUYN” stands for “Attack immediately.” Also very common 
are number groups of five or six digits. 


A cipher works with the elements of a message, the individual 
letters. A “substitution” cipher uses another letter or a number 
\o represent each letter of the alphabet. A “transposition” cipher 
scrambles a message in a systematic way that only the recipient 
can understand. 


In this volume, we'll try to maintain technical accuracy, but 
sometimes it’s not worth the effort. When dealing with in- 
dividual codes and ciphers, we’ll use the proper terms because 
otherwise we'd cause confusion. In general discussions, however, 
it’s not necessary to try for technical perfection. For example, 
when we speak of a nation’s “diplomatic codes,” we include 
both codes and ciphers. Likewise, the term “code-breaker” 
doesn’t mean a person who breaks only codes and leaves ciphers 
alone. The term “crypto-system” can apply to codes, ciphers, or 
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mixtures of both. We speak of a secret message’s being “en- 
crypted” when we mean one or the other, without being specific. 
In code-breaking, for example, the technician works with en- 
crypted messages, and his first task is to find out how they were 
encrypted. The “crypto-system” might be code, cipher, or both. 


As we study various code and cipher systems, we’ll find that, 
in practical use, there are many mixed crypto-systems. A simple 
substitution cipher is easy to crack, but when mixed with a 
transposition, the difficulty for the code-cracker is increased out 
of proportion. Likewise, many nations using a code book will 
safeguard against casual penetration by enciphering their code 
groups. 


MESSAGE CONCEALMENT 


There’s one general type of secret writing that’s not really a 
code or cipher, but depends upon concealment. There are many 
techniques of concealing secret writing, from secret compart- 
ments in ordinary objects to microdots. We'll run through these 
briefly. 


SECRET INKS 


There are many chemicals which will produce colorless ink 
that becomes visible when developed with another chemical. 
Iron sulfate produces colorless writing, until the addressee 
develops it with a solution of potassium cyanate, when it turns 
blue. Copper sulfate forms blue crystals that dissolve to become 
a colorless ink. Treating the paper with ammonia fumes brings 
out the secret writing in red. 

Phenolphthalein is the active ingredient in EX-LAX® and 


other laxatives. It’s also available in tablets and as a white, taste- 
less powder that’s hard to dissolve in pure water. Mixing one 
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tablet of phenolphthalein with half an ounce of ammonia water 
avd an Ounce of water gives a colorless ink that becomes visible 
vlien treated with sodium carbonate or other alkalis. 


Some secret inks develop by heat. Milk, for example, will turn 
'wown when the paper is heated. A solution of one part alum 
i 100 parts water provides an ink that shows when the paper 
is treated with a hot iron. So does writing with a sugar solution. 


I'he purpose of invisible ink is to avoid showing that the mes- 
“ipe even exists. Practical use involves writing an innocent letter 
i) the addressee and writing the secret message on the back or 
lwtween the lines. In so doing, it’s important to avoid tell-tale 
«ratches on the paper. This is why persons using secret inks are 
careful to apply it only with a ballpoint pen or, more commonly, 
# cotton swab. This is to avoid scratching the paper as a con- 
ventional pen nib does. The disturbed paper fibers are visible un- 
der a magnifying glass. 

If the writer uses cotton swabs, he can’t use too much liquid 
ot the paper will swell and buckle. If he’s writing on paper with 
starch “sizing,” the texture of the coating will be disturbed. Yet 
another way to use a secret ink is to soak another sheet of paper 
with the ink and to let it dry. When dry, the writer uses it as 
4 secret ink “carbon paper,” sandwiching it with the letter so that 
when he writes on_it the ink will press off onto the paper 
underneath. Another, slower way is to write on a blank sheet 
of paper and sandwich it with another, allowing ambient 
moisture to transfer the writing to the second sheet. This requires 
pressing both sheets together under a stack of books for many 
hours. 


There are several ways of detecting secret writing. One is to 
use a cage device with several brushes or swabs in a row, each 
with a different developing chemical. This technique, used 
during WWII, would sometimes disclose secret inks.! 


Working on the disturbed fibers in the paper seems to be the 
most promising way to detect secret inks, and sometimes 
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applying iodine fumes will make them show. British scientists 
have developed a “universal developer,” using radioactivity, 
which detects many secret inks.” 


Another problem with secret inks is the physical parapher- 
nalia required. A secret agent who tries to bring the materials 
in with him risks exposure by alert customs officials and counter- 
espionage agents who normally frequent ports of entry. A set 
consisting of a vial of chemical and some cotton applicators al- 
most screams, “secret ink,” which is why there have been serious 
efforts to disguise such chemicals. The chemical can be put into 
solution, used to saturate an article of clothing such as a 
handkerchief, and allowed to dry. German agents devised this 
technique during WWI. Only a rigorous examination would 
reveal secret ink concealed this way. Having the secret ink on 
a pad of paper which the agent uses for “carbons” is another 
solution. The best is for the agent to obtain the chemicals in- 
country. There are many commonly available materials useful 
for this. : 


GRILLS 


A grill can be an actual paper grill, or a simple system such 
as using every tenth word as the actual message. Let’s say that 
our message is “COME AT ONCE.” If we use a system, such 
as making every tenth word the message and filling in the spaces, 
we might get a result like this: 


“Dear John; 


I tried to ask Mama not to COME, but I couldn’t reach 
her. See, she was not AT home. It’s true that I tried much 
more than ONCE.” 


Using every tenth word makes for a very long letter, and some 
will designate every fifth or sixth word. This is more awkward, 
and often results in strange phrasing. 
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\ paper or cardboard template with slots for the location of 
ie hidden words is shown in Figure 1. 


fled to ask Mama nat ta come, but I couldn’t reach 
=i ee, she was not at home. It’s true that I 
fied much mare than once. 


neo ask Mame aot te come. bus fT sculan’% 
ne was net at heme, Ie'e true that i 


WUGR ware than once. 


Figure 1 


A template grill has holes where code words appear. 


Ihis shows why we almost never see grills anymore. The slots 
are of fixed sizes, but words vary in length. This makes a grill 
very awkward to use. We'll look at an ingenious one in the 
transposition cipher chapter, though. 


OPEN CODE 


Less awkward to use is the open or jargon code, which uses 
innocuous and ordinary words to denote important data. A letter 
written by a spy to his controller might read this way: 
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“Last week, I went on a trip into the country. Along the 
way to the farm, 120 miles southeast of my home, I saw 
3 cows strolling along the road. At the farm, there were 
another dozen cows, about 100 horses, and two dozen 
mules.” 


In this code, “cow” stands for tanker aircraft, “horse” means 
fighter, and “mule” stands for bomber. The farm is obviously an 
air base, located 120 miles southeast of whatever reference point 
the spy calls “home.” 


THE PINHOLE CIPHER 


One way of sending a concealed message is almost totally out 
of use today, although it’s very simple. This involves pricking a 
pin-hole in each letter making up a message on a printed page. 
The message can be concealed in a magazine, for example, and 
when the addressee receives it, he simply looks for the article 
with pin-holes in some of the letters. To help him, the sender 
can prick a hole in front of the title on the table of contents. 


The problem with this technique is that anyone looking for 
it will find it quickly by running his fingertips across the page. 
This is an old trick and probably every counter-espionage agent 
and customs officer in the world knows about it. 


MESSAGES DISGUISED IN DRAWINGS 


According to legend, Robert Baden-Powell used drawings to 
conceal diagrams of military fortifications as he scouted for the 
British Empire. He adopted the disguise of a butterfly collector 
and, equipped with a net, pencils, and pad of paper, noted the 
details of enemy forts and drew them into the drawings of but- 
terfly wings. 
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\nother old dodge is the architectural or landscape drawing. 
\ «vide example is shown below in Figure 2. This illustration 


vows how it’s possible to conceal the dots and dashes of a 
wyorse message as blades of grass. Although this was a workable 
sea for its day, not everyone can draw well enough to make 


+ passable drawing, and the time involved makes this technique 


a tical. 


Ww AU Ad hag hb fA ol 


Figure 2 


Drawings are one way of conveying a secret message. 
The blades of grass are actually morse code. 


MICRODOTS 


German scientists devised this system for use in World War 
Il. The “microdot” is a tiny disc of fine-grain, high-resolution 
microfilm which contains a page of writing, visible only with 
extreme magnification. A microdot looks like a small and shiny 
black disc, about 1/32” in diameter. With a tiny dab of glue, 
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it fits at the end of a sentence where a period would be, and will 
pass casual inspection. Yet, anyone looking at the paper under 
strong light might, if the light strikes it right, wonder why one 
of the periods is shiny. Some operators hid the microdot under 
the envelope flap or under the postage stamp. Indeed, the 
microdot’s tiny size made it possible to hide almost anywhere. 


Making microdots requires a special camera and film to 
photograph the pages. Careful developing yields a negative 
which the operator has to cut out of the film frame with a special 
tool that looks like a tiny hole punch. Reading a microdot re- 
quires either a microscope or a special enlarger to bring the 
image back to normal size. Often, the sender gains extra security 
by not using “clear,” or plaintext, but encrypting his message. 
This is an extra obstacle for anyone who finds the microdot. 


Concealment systems have very little going for them, and 
several drawbacks, which is why they’re rarely used today. One 
problem is that they can take too long to arrive. A letter to 
another country can take weeks in transit, while a radio signal 
is instantaneous. Another is that some require special equipment 
which can be compromising in some situations. Materials for 
secret inks are hard to explain away during a customs search. 
A set of lenses and tools for making microdots suggests “spy” 
very strongly. 


SEEKING A CODE 


There’s no ideal means of secret communication. All have 
some drawbacks, but some are better than others. Let’s look at 
some desirable qualities of codes and ciphers before we look at 
specific examples. 


A very important point is simplicity. There are some 
practically unbreakable codes and ciphers that are so awkward 
that you need a Ph.D. in mathematics to understand them. A 


Secret Writing 17 


“ule or cipher system is likely to see use by ordinary people, 
fie, working under stress. Simplicity helps. 


\nother advantage of simplicity is saving time. A cipher that 
‘squires an hour’s work to encipher a few sentences isn’t cost- 
-Hlective, The sender may not be able to afford the time. It also 
4ws down turn-around time, if the sender needs a reply. 


ihe system should require no equipment or compromising 
iw uments if the person is going to be doing anything clandes- 
une A code book or a cipher machine causes no problem a- 
inurd a warship or at a military base, but if the user is going 
») undertake a secret mission, either is a liability. This is the same 
roblem as with secret inks or microdots. As we'll see, there are 
ame ways of reducing the size of or otherwise disguising code 
ki ys 

it's also helpful if the system is error-free or fairly immune to 
esrot, Enciphering messages is difficult enough, and subject to 
esvors, Some systems, such as the “autokey” cipher, allow no 
evvor atall. A single mistake, by the person who enciphers, trans- 
wits, or receives the message, will make it total garble. A good 
yatem doesn’t absolutely prevent errors, but the effect only 
wipes out one word or phrase, not the entire message. 


Secret writing is a discipline in itself, almost like another 
vulture. It requires a different way of thinking. 


CONVENTIONS IN SECRET WRITING 


I'he purpose is to confound unauthorized persons trying to 
read the message. A basic principle is to avoid giving the code- 
ireaker any help, such as punctuation or word breaks. No 
modern cipher has any punctuation marks in the ciphertext. 


Likewise, no modern code or cipher leaves any part of the 
message in clear. A couple of centuries ago, secret agents used 
short codes to disguise the meanings of critical phrases. A mes- 
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sage thus might read: “Meet me at 36485.” This system offered 
very little security, despite the high hopes of the code’s compiler, 
because it disclosed several elements of the message while con- 
cealing only one. 


Another step is to break up all of the text into five-letter or 
five-number groups. This is to hide word breaks and to mimic 
codes. It makes a code-breaker’s task tougher if he has to strug- 
gle to determine whether he’s dealing with a code or cipher, and 
since it’s customary to use five-letter groups in codes, arranging 
ciphertext in similar groups helps. 


Another convention is to use “nulls,” or meaningless letters 
or numbers, to fill out the text. To make even groups, it’s im- 
portant to have a certain word or letter count. If there are only 
a few spaces to fill, several Xs will do. Longer spaces require 
more letters, and some cipher clerks use their imaginations to fill 
the spaces. Some use common quotations, such as the Pledge of 
Allegiance, or the Lord’s Prayer. Others may use poetry. One 
cipher clerk who did caused a classic misunderstanding. 


In the Pacific Theater during WWII, Admiral Halsey had 
created a sub-unit of his Third Fleet, called “Task Force 34.” 
During the Battle of Leyte Gulf, Admiral Kincaid sent a message 
to Halsey, asking him where Task Force 34 was, as he needed 
its support. The Commander in Chief, Pacific, Admiral Nimitz, 
heard this, and sent Halsey a message asking him the same thing. 
The cipher clerk, however, added a few words of his own to fill 
out a line. There are several versions of this story, but the most 
common one is that the clerk chose a line from Tennyson’s 
“Charge of the Light Brigade.” The message finally read: 


WHERE IS TASK FORCE 34 
AS ALL THE WORLD WONDERS 


Halsey received the message with the nulls included because 
his code clerk had mistakenly thought that they were part of the 
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sewage. As he read it, he thought that it was an insulting 
“eesage, Coming from the Pacific Commander, and he became 
very angry. He turned his ships around and headed South to go 
help Kincaid? 

Yet another convention is to paraphrase all messages before 
veleasing them for publication. Winston Churchill did this in his 
4« volume History of the Second World War because including 
ihe message in cleartext might have compromised British crypto- 
syeiems still in use. 
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Substitution Ciphers 


Ax we've seen, a “substitution” cipher is one in which one 
letter Or number stands for each letter in the message. Although 
iis is the principle, substitution ciphers can become quite com- 
plicated, with groups of letters or numbers denoting each letter 
in the plaintext. We’ll also see that there are ways to make a 
ade-breaker’s life hell with a few simple tricks. Let’s begin with 
ihe basics, though. One important principle that dominates 
‘typtology, and which many ignore, is “K.LS.S.” It means 

Keep It Simple, Stupid.” A very complicated cipher can totally 
confound a code-breaker, but it can cause as much trouble to 
ihe recipient. 


We're also going to avoid any ciphers which use symbols. The 
Sherlock Holmes story, “The Adventure of the Dancing Men,” 
lus an example of such a cipher, which is best left to the fiction 
writer. The symbol substitution cipher may look mystifying but 
offers no additional security. The disadvantage is that it’s harder 
{0 transmit over the telegraph, telephone, or radio. 
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SIMPLE SUBSTITUTIONS 


A “simple substitution” is a cipher with a single letter or 
number replacing each letter of the plaintext. One simple cipher: 
is this one: 

ABCDEFGHIJKLMNOPQRS TUVWXYZ 
RSTUVWXYZABCDEFGHIJKLMNOPQ 


This is so simple that we may even call it “simple-minded.” 
The cipher alphabet is simply shifted a few spaces but still in 
order. With this cipher, we would encipher the plaintext “Come 
at once” this way: 


TFDV RK FETV 


This message may appear incomprehensible, consisting 
mainly of consonants, but an experienced code-cracker might 
count the letter frequency and deduce that one of the three letters 
which appears twice, T, F, or V, stands for the letter “E,” the 
most common letter in English. 

Of course, a longer message would be more helpful, because 
the frequency count’s likely to be less typical with short mes- 
sages. 


Let’s try a simple substitution cipher using numbers: 


ABCDEFGHIJKLMNOPQRS TUVWXYZ 
1718192021 22232425261 23 45 67 8 9 10111213141516 


This isn’t very practical, because it offers few possibilities for 
confusing a code-breaker. “Come at once” would have to be 
written this way: 


19-5-3-21 17-10 5-4-19-21 
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i ve dashes are necessary to prevent confusion. Without them, 


‘he addressee would have as much trouble as the code-breaker. 


ike mexsage would look like this enciphered: 
195321 1710 541921 


Someone deciphering it might start by thinking that the first 
i stands for “K,” and go on to get a plaintext that begins with 
RSOMLK.” 


JUMBLED ALPHABETS 


li helps slightly if the letters comprising the cipher section are 
ait of normal alphabetical order, instead of reading “A, B, C,” 
- , even if the sequence is broken at some point. One way to 
Jo itis to use a “key word” to govern the arrangement of the 
initers, We first write the key word and arrange the remaining 
letters of the alphabet behind it in order. The only strict re- 
juirement for this sort of key word is that it have no repetitions 
of the same letter. Using the key word “company” we get: 
,UCDEFGHIJKLMNOPQRSTUVWXYZ 
/OMPANYBDEFGHIJKLQRSTUVWXZ 


In this cipher, “Z” stands for itself, but this isn’t a real 
jroblem. For somewhat better security, we do something else. 
We write the key word at the top of a block and the remaining 
letters below it, in rows: 


COMPANY 
BDEFGHI 
JKLQRST 


UVWXZ 
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Now we lift the letters in columns and write them under tli 
plaintext alphabet: 


ABCDEFGHIJKLMNOPQRSTUVWXY 7 
CBJUODKVMELWPFQYAGRZNHSYI1 


All of these simple substitution ciphers share the weakness 0! 
being vulnerable to frequency count analysis. Also, the ar 
rangement of the words provides some give-aways to the code- 
breaker. For example, in our original message we have the two- 
letter word “AT.” There aren’t many two-letter words in 
English. They’re easy to remember and spot. 


We can make the ciphertext message less obvious by breaking 
up word lengths. If we put it into five-letter groups, we get this: 


TFDVR KFETV 


At first sight, this could be anything. These groups could easily 
be from a code book, or the result of a transposition. Still, such 
a message is vulnerable to a frequency count. 


POLYPHONIC SUBSTITUTION 


The next step in producing a difficult cipher to break is the 
“polyphonic” cipher. There are several systems in use, but let’s 
keep it simple and use a letter system. Each letter will have a 
two-letter group representing it. 


A problem with “digraphs,” two-letter groups, is that if one 
letter drops out during transmission, the entire sequence shifts 
out of phase, snarling the message. The addressee has to do some 
trial-and-error to determine which letters or letters were lost, and 
which represent the message as sent. To prevent confusion for 
the person who receives it, we'll establish the rule that the two- 


Substitution Ciphers 25 


vey groups begin with a letter from A-L and that the second 

ey will always be between M-Z. We'll have several groups 

‘eywesent the most common letters in English, which we 
‘yeady know are E, T, A, O, N, R, I, S, and H. 


i keGHE$EIs KEMNOPQRSTUVWX Y Z 
\ ) HOC PC RCMDMDNDOD PDQEMENEOE PEQFMEN FOF QF PGMGNGO 
ag GVGR GSGT GUHOHM 
WP HQHR HSHU HVHZIM 
10 IP1Q IRIS ITIVIX 
IN JOJP JQIUR JSITIU 
1x JZKM KNKO KQKPKR 


With this, let’s encipher the message “I need you. Come at 
vce.” We'll use a different digraph for each of the common 
iters to avoid building up anything that will show in a 
feqquency count. Here’s what we get: 


it EMBQHPBP GNENFO BOGTDQGQ AMEN HUIRBOJX 


(he only digraph which repeats is “BO,” which stands for 
«Now let’s make it a little more difficult by breaking the 
words up to foil any intuitive substitution: 


(EMB QHPBP GNENF OBOGT DQGQA MFNHU IRBOJ XMOVP 


We also did something sneaky here. Note the last group. 
{here weren’t enough letters to produce an even group, and 
ihere were four spaces to fill. The trick is to add “nulls,” letters 
(hat don’t mean anything, to fill the spaces. The receiver will 
know that the last letters, “MOVP,” are meaningless because 
they are from the second half of the alphabet, and can’t begin 
any digraphs. 
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An easier cipher to construct uses a grid, and is also pol) 
phonic. In this case, we'll also set up a couple of arbitrary rule: 
We'll use two-letter groups to denote each letter. We'll also s:\ 
that one of the first three letters of the alphabet, A, B, and ( 
will always be the first letter of each digraph. This is very im 
portant to avoid the addressee’s becoming confused if one lette: 
is lost or garbled in transmission. If one digraph is unclear, Ix 
can go on to the next one and figure out the missing letter afte: 
he completes decryption. Let’s set up our grid, starting with the 
most common letters at the top: 


Cipher Letters: ABC 

Plaintext: ETA Cipher: XYZVW 
ONR PUQML 
ISH KFGJ 
BCD IEO 
FGJ BCD 
KLM RT 
PQU AS 
VWx H 
YZ N 


This provides another security measure; several choices for 
each high-frequency letter. To encipher, we start with the letter 
at the top of the column containing the letter from our message, 
and choose one from the right-hand set of cipher letters. We can 
encipher the letter “E” FIVE different ways: AX, AY, AZ AV, 
and AW. 


Let’s see how this can mess up the frequency count. We'll 
encipher “I need you. Come at once.” again: 


INEEDYOUCOMEATONCE 
AKBPAYAZCIANAUCABIAQCRAVCXBYALBMBEA W 
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liveaking this up into five-letter groups gives us: 


\K UPA YAZCI ANAUC ABIAQ CRAVC XBYAL BMBEA W 


We've got one letter left over. To fill out the group, we'll add 
iu nulls, taken from the right-hand columns because they can- 
wot begin any groups: 


\KUPA YAZCI ANAUC ABIAQ CRAVC XBYAL BMBEA WNHAS 


li such a short message, there’s no repetition of digraphs. This 
i» not an unbreakable cipher, but the five-letter groups disguise 
ihe cipher. Also, the combination of digraphs and suppressed 
\ommon-letter frequencies will slow a code-breaker down if he’s 
limited to paper and pencil. 


THE PLAYFAIR CIPHER 


An even more secure method of polyphonic substitution is the 
Playfair” Cipher. This was the British military cipher of the late 
Nineteenth Century, and is fairly secure against casual code- 
leaking. We start with a key word that does not repeat letters, 
and write the rest of the alphabet behind it: 


ori alas 9 EO” 
<—AQKXO 
Sr hwe 
xn Ov 
NHA MS 


What we now have is a grid of five letters by five letters. To 
make it come out evenly, we had to drop the — and decide 
that any word containing that letter will be written with an “T. 
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With this, let’s encipher the message “I need you. Come 3 
once.” The first step is to break it up into two-letter groups, 01 
digraphs: 


IN EX ED YO UC OM EA TO NC EX 


There was one set of double letters, in the word “NEED.” || 
was necessary to break that set up by placing an “X” between 
them, or we would not be able to encipher the message properly 
To make the message end with a set of two letters, we also added 
another “X” at the end. 

To encipher, we follow several rules: 


If both letters of a pair fall in the same TOW, we replace each 
letter with the one to its right. For example, “MO” would 
become “PM.” If the letters are in the same column, we replace 
each by the letter beneath it. The pair “YO” becomes “GY” and 
the pair “UC” becomes “CN.” Note that in the second pair, “C” 
was above the “U.” We simply ran back to the top of the 
column, so that we used the “C” to encipher the “U.” 

Some pairs will have letters that are not in the same row or 
column. “TO” is one such. We then replace the “T” (in bold) 
by running across the row until we're right under the column 
with the “O” and using that letter, which is “Q” (in parentheses). 
We replace the “A” by going across until we're right on top of 
the “T,” and using the “A.” To be consistent, we remember the 
rule always to encipher the first letter of the digraph first, no 
matter where it is in the grid. Thus, we always get “QA” and 
not “AQ.” 


C O M P (A) 
N Y BD & 
F G H I «Xk 
L @ & &§ fF 
U VW x gZ 
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Working through the entire message, we get: 
in EX ED YO UC OM EA TO NC EX 


ft) DZ NE GY CN MP KE QA FN DZ 


11, decipher the message, we write out a grid using the key 
svt as a guide, and work it backwards, reading to the left of 
‘ters in the same row, above letters in the same column, etc. 
| he strength of the Playfair Cipher is that the cipher letter for 
« li message letter will vary according to the other letter in the 
pal! Looking at the first digraph, we see that “IN” is “FD. 
ihowever, if it were “ON,” it would come out as “CY,” two 
iipletely different letters. This is a serious complication for the 
«le breaker, who must use a digraph frequency count to break 
vat (hits cipher. 


THE DELASTELLE CIPHER 


We can call this a “double substitution” cipher because we 
i ipher the ciphertext as well.! The Delastelle starts with a 25- 
jace grid, dropping the “J” and using the “I” for both. On top 
su down the left side are the digits 1 to 5. Enciphering is by 
ihe coordinate method, first with the left column and then the 
lit in the top row: 


1 
if 
2N 
3F 
4L 
5U 


<ODQKON 
Emm wesw 
Xne Own 
NHAM SUH 
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We'll encipher the usual message, but write the coordinate: 
vertically: 


I NEED YOU COME AT ONCE 
3 222.2 215 bI1T2 14 1212 
4 1554 2.2)1 1235 55 2115 


Now we generate the cipher letters by reading the coordinates 
horizontally. 


322222151112141212415542211235552115 
GYYACOPOOLZQNOKZNA 


We break this up into five-letter groups: 
GYYAC OPOOL ZQNOK ZNA 


That left a couple of empty spaces. Rather than inserting nulls, 
we can set the message up in three six-letter groups as well: 


GYYACO POOLZQ NOKZNA 


Deciphering is the reverse of these steps. Security is about as 
good as the Playfair, but for maximum security it’s best to use 
a one-time keypad. 


THE CIPHER WHEEL 


The cipher wheel (Figure 3) is a simple idea which can create 
ciphers of varying complexities. The alphabet in the outer wheel 
is straight-on, while the inner one is reversed. The simple way 
to use it is to put the two “A”s together, and use the inner wheel 
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find substitute letters for those in the outer wheel. This is a 


seple substitution with no more strength than a paper-and- 
sewsil list, However, the cipher wheel offers several different 


sales of use. 


Figure 3 
A simple cipher wheel makes it easy to 
encipher messages in a variety of ways. 


I'he simplest one is the changing key letter. Each message can 
ie in a different cipher, and the sender simply makes the key 
letter the first one of his message. The key letter 1s the one on 
‘he inner wheel the user places next to the “A” on the outer 
wheel. This provides 26 possible ciphers. Unfortunately, each 
individual cipher is no harder to decipher. 


The key word is more difficult, and provides a true “poly- 
alphabetic” cipher. This is a cipher that uses more than one 
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alphabet arrangement for enciphering, The key word’s lette:: 
indicate which setting to use for each letter in the message. Fv 
example, let’s set up the message; “I need you. Come at once’ 
with the key word “company:” 


To encipher the first letter of the message, the user places the 
“C” of the inner wheel next to the “A” on the outer whee! 
Before enciphering the “N” he sets the letter “O” next to the 
outer wheel’s “A.” This generates a different cipher. As 
“COMPANY” has seven letters, the message will be enciphered 


in seven different ciphers, creating difficulties for the code- 
breaker. 


ABCDEFGHIJKLMNOPQRSTUVWXYZ 


NHUKJIHGFEDCBAZYXWVUTSROPONAL 


ZYXWVUTS 


Figure 4 


Similar to the cipher wheel, the cipher slide 
Shown here is easy to make and easy to use. 


The cipher slide (Figure 4) is the next gimmick which can 
provide the same type of changing substitutions. The main 
advantage of the slide is that it’s easier to make neatly, requiring 
only a couple of pieces of paper and a typewriter. There are no 


problems with spacing the letters correctly around the periphery 
as with the cipher wheel. 
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\i| of these are based upon the polyalphabet table. It looks 


i DEFGHIJKLMNOPQRSTUVWXYZ 
A ECDEFGHI JELMNOPORSTUVWXY 
+ /ABCDEFGHIJKLMNOPQRSTUVWX 
Y7ABCDEFGHIJKLMNOPQRSTUVW 
VXYZABCDEFGHI JKLMNOPQRSTUV 
YWXYZABCDEFGHIJKLMNOPQRSTU 
UVWXYZABCDEFGHIJKLMNOPQRST 
i UVWXYZABCDEFGHIJKLMNOPQRS 
/TUVWXYZABCDEFGHI JKLMNOPQR 
HS TUVWXYZABCDEFGHIJKLMNOPQ 
oOkS TUVWXYZABCDEFGHI JKLMNOP 
rORSTUVWXYZABCDEFGHIJKLMNO 
OPQRSTUVWXYZABCDEFGHIJKLMN 
Re Ue eee ea. 
eS GUN ea eager Neate fore 
Pe ee ee ee a 
Se ee ee eae 
1K LMNOPQRSTUVWXYZABCDEFG 3 
| JKLMNOPQRSTUVWXYZABCDEFG 
ti J KLMNOPQRSTUVWXYZABCDEFG 
GHIEJKLMNOPQRSTUVWXYZABCDEF 
'}GHIJKLMNOPQRSTUVWXYZABCDE 
1} GHIJKLMNOPQRSTUVWXYZABCD 
DEFGHIJKLMNOPQRSTUVWXYZABC 
(DEFGHIJKLMNOPQRSTUVWXYZAB 
NCDEFGHIJKLMNOPQRSTUVWXYZA 


; ingly 

Here we have 26 possible ciphers. We can use these singly, 
ot with a key word. Let’s try a simple one, using the key word 
‘LOVE.” 
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abcdEfghijkLmnOpqrstuVwxyz 


ABCDEFGHIJKLMNOPQRSTUVWXKYZ 
ZABCDEFGHIJKLMNOPQRSTUVWXY 
YZABCDEFGHIJKLMNOPQRSTUVWX 
XYZABCDEFGHIJKLMNOPQRSTUVW 
WXYZABCDEFGHIJKLMNOPQRSTUV 
VWXYZABCDEFGHIJKLMNOPQRSTU 
UVWXYZABCDEFGHIJKLMNOPQRST 
TUVWXYZABCDEFGHIJKLMNOPQRS 
STUVWXYZABCDEFGHIJKLMNOPQR 
RSTUVWXYZABCDEFGHIJKLMNOPQ.: 
QRSTUVWXYZABCDEFGHIJKLMNOP 
PQRSTUVWXYZABCDEFGHIJKLMNO 
OPQRSTUVWXYZABCDEFGHIJKLMN 
NOPQRSTUVWXYZABCDEFGHIJKLM 
MNOPQRSTUVWXYZABCDEFGHIJKL 
LMNOPQRSTUVWXYZABCDEFGHIJK 
KLMNOPQRSTUVWXYZABCDEFGHI J 
JKLMNOPQRSTUVWXYZABCDEFGHI 
IJKLMNOPQRSTUVWXYZABCDEFGH 
HIJKLMNOPQRSTUVWXYZABCDEFG 
GHIJKLMNOPQRSTUVWXYZABCDEF 
FGHIJKLMNOPQRSTUVWXYZABCDE 
EFGHIJKLMNOPQRSTUVWXYZABCD 
DEFGHIJKLMNOPQRSTUVWXYZABC 
CDEFGHIJKLMNOPQRSTUVWXYZAB 
BCDEFGHIJKLMNOPQRSTUVWXYZA 


NX xXE<CHNAPHVOAZZrAGHK DMA AMIAw>D 


With this, we write “LOVE” repeatedly above our plaintext, 
and use the cipher column corresponding to each letter to 
encipher our message. The plaintext letter is at the left, and we 
run across each row until we find the letter under the key word 
letter. The text “I need you. Come at once” would read: 

Key word: LOVELOVELOVELOVELO 


Plaintext: I NEEDYOUCOMEATONCE 
Ciphertext: dbraiqhkjajalvhrjk 
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| he strength of even a four-cipher polyalphabet system is ob- 
sus, Here we see two digraphs, “ja,” which have entirely 
‘iiferent plaintext meanings. The most common letter in 
tawlish, “E” becomes “1” “a” and “k.” 

ihis type of cipher is much stronger than the simple sub- 
M\ution, but as we'll see in the code-breaking chapter, vul- 
serable to analysis. A weak point is the use of only four ciphers. 
‘sing a longer key word would increase security because it 
vould bring in more individual ciphers. There is another way 
{ wing the alphabet table that is perhaps the most secure of all, 
jit its weakness is that one garbled letter can make it impossible 
iw the addressee to decipher the message. This is the “autokey.” 


THE AUTOKEY CIPHER 


his cipher, in its simplest form, requires no key word. The 
ender and the addressee agree that each message will always 
jeyin with a certain letter, for example “A.” Another way to 
Jecide the key might be to use the first letter of the sender’s sur- 
ume. Yet another way is to use the first letter of the day of the 
week it is sent. This can cause problems, though, with delayed 
wessages. The addressee will start getting garble and will have 
io ry working backwards until he finds the right letter. 


Ihe principle of the autokey is that the cipher letter de- 
\ermines the cipher used for the next letter. Let’s work again with 
ihe same message as above, and use the alphabet table used with 


ihe “LOVE” keyword exercise: 
I NEED YOU COME AT ONCE 


We'll begin with cipher alphabet “A” to encipher the first 
letter of the message, which is “I.” We go down the left column 
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until we find “I” and take the letter next to it in the first cipli 
column, to get “S.” We use the “S” cipher alphabet to enciphi 
the next letter, “N.” This gives us “F.” Looking at the top ry 
we find the “F” column, and we find the letter “B” in the san 
Tow as the “E” in the extreme left column. Working this wa: 
the final result is: 


I NEED you COME AT ONC, 
S FBXU WIO MYMI IP Bom, 


This short message used twelve cipher alphabets, and only thi 
“B,” and “O” got used twice, but for a different letter each tim 
“M” was used three times, twice for the same letter, and ther 
were four “Is, only twice for the same letter. If we were to re 
arrange this message into five-letter groups, it would be, for «ll 
practical purposes, unbreakable. This may appear hard to be 
lieve, but even with the assistance of a super-computer, 4 
message this short, and with no repetitions, is totally secure. 


The fatal flaw in the autokey is that, if there is an error in en 
ciphering or transmitting it, the rest of the message is garbage 
In deciphering, the addressee looks up the first letter of the 
ciphertext, “S,” in the “A” alphabet, getting “I.” He then uses 
the “S” alphabet to find the next letter’s plaintext equivalent, 
which is “N.” Since each letter decipherment depends on the 
Previous one, a single break in the chain makes the rest of the 
message indecipherable. 


The great strength of the autokey is the almost-random en- 
ciphering key. With enough messages, however, it’s possible to 
force a solution because there are still only 26 alphabets. It’s 
Possible, of course, to construct a cipher table with more than 
26 alphabets, but this becomes both clumsy and error-prone in 
a pencil-and-paper cipher. To 8el a practically unbreakable pen- 
cil-and-paper cipher, we have to go back to numbers. 
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COORDINATE NUMBER CIPHERS 


\ more practical number cipher makes use of a grid. bee 
» «heckerboard with 10 spaces on a side, numbered from 
0" This provides 100 spaces, which we can use to at a 
lreqquency count of the ciphertext. We do this - inclu pi 
sy possible coordinates for the common letters. This bes - 
| the “pocket codes” used by General Leslie R. ees i g 
'» “Manhattan Project” in WWII Let’s see how this looks: 


1234567890 
1 ETAONRISHB 
2 C£DEPGHIIEL 
3 ETAONRISHM 
4 NOPQRSTUVW 
5 ETAONRISHX 
6 YZETAONRIS 
7 RISHETAOIN 
8 EOTANSHRLU 
9 TDBREFEDTA 
0 SRHRDLUETO 


I{ we use the usual coordinate system, we can take the arm! 
trom the left-hand column as the first digit, and use om one oe 
ihe top row as the second digit to represent re anne bs ao 
alphabet. We have 10 “E”s in 100 spaces, whic ee sis 
different two-digit numbers to represent it. Using - is He, 
«ould encipher “I need you. Come at once.” several ways: 


2181 
171511512261142142309513125415 

6967236305614221543081334766352195 
72553195986 1002 1783075840982412108 
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Few double-digit combinations repeat. The letter “C” ha, 
only one combination, “21.” This cipher can easily hold up 
code-breaker for a few hours, but it’s slightly clumsy to use. Let’s 
try another type of grid, one used by the Soviet Secret Servic 


during WWII. In this one, we'll use both single and double-digit 
numbers: 


8 
9 


GMaAmMo 
OUxA- 
Any >p 


B 


This cipher doesn’t follow the usual practice of Starting with 
the left column. To encipher, we start along the top row. One 
obvious point about the way we’ve set up this cipher is that the 
most common letters in the alphabet, E, T, A, O, N, R, L, =, A. 
are represented by only one digit of ciphertext. Let’s see how this 
works with our standard message: 


I NEED YOU COME AT 
6 40018 79339 


ONCE 
083880 21 34080 


combination “08” can mean “C” or “EH.” This is an annoyance 
which can slow down the addressee’s work. Another, and more 


As we'll see in the chapter on code-breaking, and as we’ve 
suggested here, the weakness of any cipher is in the patterns left 
in the enciphered message. A code-breaker can intuitively see 
that a two-letter code word can easily be “a1, “18 “AN,” 
“AT,” “ON,” or “TO.” With this, he can guess that any similar 
combinations farther on in the message stand for the same 
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tiers, Likewise, when he sees two similar letters or numbers, 


vel us “88” he may guess that they are doubled ee 
seonants, again very common in our language. ee ae ul 
+l combinations, and this again provides an insight i 

heiden meaning. 

i ven with multiple-alphabet ciphers, there is a seb 
sfier a certain amount of ciphertext. A cea ieeio ge 
sts of two or more messages against each other an - pried 
sepetitons. Once he spots a pattern, he’ll have a start at est 
ito the cipher. Only very short messages are proof panes ed 

iucking. We'll go further into the reasons for this me cn ab 
tweaking section. For the moment, let’s note t a arene 
solute guarantee against technical code-breaking is a 

bey. The principle is elementary, and easy to use. 


RANDOM NUMBERS 


We need a list of random numbers, and we add each ee 
\ « number in the ciphertext, using non-carrying soap 
lyin again with the message from above. To this we she 
ot of numbers generated by a peor rereeaes = roi 
iicluded in a small hand calculator, the CASIO fx-82B. 
| iwure 5 on page 40). . . 

'nciphering one code or cipher text with oe : bie 

, i _ i mmon tactic tha 
‘superencipherment, and is a co 2 
daironenie: sls difficulties for the code-breaker. We’l 
encounter this again in subsequent chapters. . 

Now we add them, but in a special way for fog staan 
his is non-carrying addition, aaah aes ; eae 7 

oe bh bs - ” a A 
System,” or “Chinese arithmetic. e ad 
si simply don’t carry forward the first digit of any sum act 
than 9. This is for brevity, but also because carrying num 
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forward would spoil the random distribution.* Here’s how this 
ort of addition looks: 


fx- 82 
fx-82B | NEED YOU COME AT ONCE 


640018793390838802104080 ciphertext 
582891645077701981458581 random numbers 


122809338367539783552561 Superenciphered version 
Random 

Number I his is our ciphertext, and because random numbers have no 
pattern, they have no systematic repetitions. This makes any 
‘lov at breaking the cipher by teasing out patterns futile. The 
'}"’ we see doesn’t stand for a repeated letter, but for the “NE” 
« the actual message. The repetition “33” stands for “Y.” We 
stu see a “93” and a “39” in the ciphertext, but these don’t stand 

‘4 reversed letters. 


1) decipher the message, the addressee needs a copy of the 
» He then subtracts the key from the ciphertext. 


1. Press INV | 


122809338367539783552561 
582891645077701981458581 


640018793390838802104080 


Serres emmeees Ihe rule for subtraction is the reverse of that used for addition. 

2. Press RAN# \! the lower number is larger than the one from which it’s to be 
ubtracted, we assume that the upper number has a “1” before 
| get the first number, 6, we assume that we’re subtracting 


To generate a three-digit random number using the Casio Sx-82B fiom 11. 


calculator, first press the INV key in the extreme upper left-hand . <i 
corner. Then press the decimal key — it has the word RAN# above [here are some problems with obtaining random numbers. 


it (second key from left in the bottom row). A new three-digit random \e can’t simply sit down and write any numbers that come into 
number will be produced each time the process is repeated. 11 heads. We'll be unconsciously including patterns. A better 


Figure 5 
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choice is to use a book with lots of statistics, such as the World 
Almanac. This offers a cheap and commonly-available mass of 
random numbers. Because we’re only interested in the numbers, 
we don’t need the current edition, and can pick up almanacs 
from previous years very cheaply in second-hand bookstores. 
Another commonly-available source is the stock and bond price 
listings in the financial pages of the newspaper. If the source is 
a printed one, we may have to include the information in the 
enciphered message. For example, the first, or tenth number 
group can be the page number we’re using for this message. Let’s 
say we obtained the random numbers for our message from Page 
67 of a certain year’s almanac. We’d arrange the message as 
follows: 


00067 12280 93383 67539 78355 25610 


Breaking the message into five-number groups and adding a 
null at the end adds to the difficulties the code-breaker will face. 
Let’s note that we can also include the page number at the end 
of the message, this way: 


12280 93383 67539 78355 25610 00067 


Another feature of using random numbers is that the five- 
number groups will also read like code groups. There is no 
scientific or mathematical way for the code-breaker to determine 
whether he’s working with a code or a cipher, because many 
codes use random-number groups. 


There are ways of generating quick and dirty pseudo-random 
numbers, but the simplest ones don’t offer much security against 
a skilled and determined code-breaker. One way is to use the 
current date, repetitively, as the additive. Another is to use either 
the sender’s or the addressee’s birthdate. This isn’t very good 


Substitution Ciphers 43 


security, and it’s possible to enhance it by using the current date 
and both birthdates in sequence. This is still quick and dirty, 
however. 


A slight upgrade is using a scientific calculator with a random- 
umber function, such as the Casio fx-82B noted above. This 
costs between ten and fifteen dollars retail. Another model is the 
Sharp Model #506, in the same price bracket. A yet more 
complex way of generating random numbers is using a computer 
program, such as the ones listed in Marotta’s Code Book.”* 


None of these are true random-number generators, however. 
Ihey all use very complex equations with subroutines to put 
\ogether strings of numbers that don’t repeat quickly and which 
have very subtle patterns. It’s only logical to see that any 
yenerating system which depends on an equation, however com- 
plex, will leave its pattern in the numbers. For most applications, 
it doesn’t matter. Most people cannot dope out a cipher that uses 
pscudo-random numbers. If there’s a good chance that a govern- 
iment will become interested in the contents of your messages, 
you'll need something more secure if you want your cipher to 
be totally impenetrable. For this, you need true random 
iiumbers. One source is a statistical table of some sort. Another 
is translating text into numbers, and we'll get into this technique 
in the chapter on codes. 


THE ONE-TIME PAD 


This is a way of providing a secret agent with sets of random 
iumbers for field use. One-time pads have been used by the 
secret services of many nations, although they were invented in 
(jsermany.® The reason for the name “one-time” pad is that each 
sheet on the pad is used once, and discarded. 
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The one-time pad is a set of grids with a number inside each 
rectangle. There are many rows of numbers that look like this: 


(4[3]7/lil4]7/9/2lslilolsi3[a| 
6/3! '7(2[3| 2/41 3/0] 


3 | 5|6|8|9| 7] 2/3] 2 
‘stile. 21812 /3| 9/4] 2| 
6/5/3/1]2]1| 5] 6 4| 3 
9/2/6|0/1/ 4] 8/0 4| 5 


| 4} 2} 5] 3} 1] 4} 5] 8] 3] 6] 9] 6] 7] 8] 2| 


Each number comes from a random numbering system, 
whether true or pseudo-random. However, the odds are that for 
an agency to go to this trouble, they’ll also produce a genuine 
random number system. 


The advantage of the one-time pad is that it’s a simple and 
unbreakable cipher system. In use, the pads are produced in sets 
of two. The agent takes one pad with him, leaving the other with 
the “home office.” He enciphers his messages, using the sheets 
in sequence off the top of the pad, and discarding it after one 
use. The decipherer at the home office follows the same 
sequence, discarding each sheet after using it because he knows 
that he’ll never get another message using that sheet. 


The major disadvantage of the one-time pad is the risk of it 
being found if one is caught. It’s a dead give-away because a 
one-time pad has no other use. Unlike a book of statistics, or 
a dictionary, there’s no plausible explanation for its possession. 


Unlike a key that the agent can keep in his head, there’s no 
way to use a one-time pad except by physically having one. This 
dictates a hiding-place, and any hiding-place is vulnerable to 
discovery through search or bad luck. 
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For certain types of high-level diplomatic and military 
messages, the one-time pad is practical. The pads are secure in 
protected offices, and the code clerks are not clandestine 
operatives. 


OTHER TECHNIQUES 


As we'll see, the substitution cipher is only one type of cipher. 
In certain cases, another type is more suitable to the task. For 
extra security, it’s also possible to combine two or more different 
methods. We'll look at different systems to understand these 
possibilities. 

There are also labor-saving devices used in cryptography, 
usually by government and corporations. These are electro- 
mechanical systems, and we'll discuss them next. 
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Electro-Mechanical Ciphers 


Electro-mechanical systems have dominated the crypto- 
graphic field during most of the Twentieth Century. However, 
their roots go back almost two centuries. 


As we noted before, Thomas Jefferson devised a cipher- 
yenerating “machine” that was very advanced for its day. 
Although it was based upon the polyalphabetical table, it offered 
lar greater security. The device consisted of 26 wooden discs 
placed upon a spindle, as shown in Figure 6 on the next page. 
ach disc had the alphabet evenly spaced around its rim. The 
letters were in different order on each disc. To use it, the sender 
rotated the first disc until the first letter of his message was facing 
him. A ruler helped line up subsequent letters. He then rotated 
the second disc until the second letter of his message was in line 
with the first. He repeated this step for the rest of the discs. At 
that point, the sender had a choice of copying any of the other 
25 rows of letters for his ciphertext. With that done, he went 
on to encipher another row. 


To decipher, the addressee had merely to line up his rotors 
according to the letters in the message, and turn the rotor system 
until he saw an intelligible line. The device offered polyalpha- 
betic security, but it was also possible to scramble the order of 
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the rotors on the spindle. This was the basis of the U. S. Army 
Signal Corps’ M-94 enciphering device, issued in 1922.) An 
advantage of the M-94 is that it’s simple to use. “Designed by 
geniuses for use by idiots” is a good description. 


(EEC EER REECE! 
(WEE 


Figure 6 


Thomas Jefferson was a “founding father” of encription. 
The device shown here is a rotor designed by Jefferson. 


POLYALPHABET THEORY 


Let’s recap the principle of polyalphabet substitution before 
getting into the complications of million-letter alphabets. We 
know that using a simple substitution is almost like using no 
cipher at all, because the cipher letters retain the frequency 
pattern of the plaintext. Cipher-makers have made huge efforts 
to suppress these ciphertext frequency patterns, and to suppress 
any patterns at all. Using more than one alphabet increases the 
problems for the code-breaker, but he can still detect patterns 
when the alphabets begin to repeat. 


The non-repetitive key, as we’ve seen, is the perfectly un- 
breakable enciphering method. The problem with it is that to en- 
cipher all of the messages needed requires an unwieldy number 
of one-time pads or other sources of non-repeating keys. It’s not 
practical to use one-time keys for all messages. There are, 
however, some workable solutions. 
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THE ROTOR MACHINES 


What if it were possible to use a series of alphabets a couple 
of hundred thousand alphabets long without repeating? How 
about a string of alphabets a million long? It isn’t practical using 
any sort of pencil-and-paper system, but during the First World 
War, and the decade after, four different inventors in four 
different countries devised what was basically the same 
imuchine.? This used rotors to encipher the message, in a fashion 
somewhat like that of Jefferson’s device. There was one critical 
difference which made the ciphers much more secure: The 
‘otors’ positions changed after every letter enciphered! 


In practice, working an electro-mechanical rotor machine is 
like typing with an electric typewriter which types a different 
letter each time we press the same key. We may press “A” a 
hundred times, and each time a different letter appears, with no 
order or pattern that we can see. 


The way this happens is the heart of the rotor machine. The 
ilevice uses an electric rotor to re-route the electrical impulses. 
lhe rotor is a thick disc with 26 electrical contacts evenly spaced 
around each face. Within the rotor are wires connecting the 
‘ontacts on one face to those on the opposite side, so that a 
circuit will open up between contacts at different positions. The 
iotor is On a spindle between two other contact plates, each with 
‘6 contacts. The device is wired between a typewriter keyboard 
and an electric printer. Let’s say we press the “A” key. The letter 
(” actually prints on the paper. The electrical current also 
«perates a solenoid which flips a tooth into a ratchet, turning the 
‘olor 1/26 of a turn. This lines up the contacts slightly dif- 
lerently. Hitting the “A” key again this time prints an “S,” let’s 
ay. The solenoid and ratchet turn the disc another increment, 
and typing “A” this time prints an “M.” What we now have is 
a polyalphabetic printer using 26 different alphabets. This is still 
aot remarkable, although it makes a good labor-saving device 
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known as an “on-line” encryption machine. This enciphers the 
message without any special effort by the operator. 


If we add a second rotor to the spindle, between the first and 
the contact plate, and a second solenoid and ratchet, we have 
an entirely different machine. The second rotor shifts forward 
one space only after the first has made a complete turn, when 
a stud on its rim trips a switch to actuate the solenoid for the 
second rotor. Now, after typing 26 letters, typing “A” again 
won’t give a “C,” but another letter, because the second rotor 
has re-routed the current according to its own wiring, which is 
different from the first rotor’s pattern. This gives us 26 x 26 
alphabets, or 676. This means that the encipherment will not 
start repeating until after 676 letters. A third rotor, which starts 
turning only after the first two have completed their cycles, 
brings the interval up to 17,576. Adding a fourth gives us almost 
half a million alphabets, and using five gives us over 11 million. 


Let’s look at a patent office diagram of a cipher rotor machine 
(Figure 7). 


5° pe . 
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Figure 7 
Edward Hebern’s “Electric Code Machine.” 
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We can see that the original idea of this early model was not 
on-line encryption, but simply enciphering. Hitting a key only 
lita bulb behind a letter on the board. The ratchets are 
mechanically operated, and this device will run on battery 
power. This makes it suitable for military field use. 


Let’s inspect the works of the famous “Enigma” machine 
(Figure 8). 
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Figure 8 


Arthur Scherbius’ “Enigma” enciphering rotor. 


We see how a lever turns the ratchet manually for each letter 
encipherment. We also see how it’s possible to set the rotor in- 
dividually for each message. A diagram at the upper left shows 
« schematic for wiring a rotor. 


Incredibly, this isn’t the last word, either in operation or the 
degree of security possible. To transmit a message, it’s necessary 
lor both the sending and receiving machine to start at the same 
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point, with rotors in both machines in the same positions. This 
means that there must be a “key,” to allow setting the rotors with 
the key letters next to a reference mark. The key can change 
every month, week, or day. During the latter part of the war, 
the Germans changed the key every eight hours. 


Various models of these machines were available on the open 
market during the 1920s. The military market was poor, and the 
inventors’ only opportunities of making enough sales lay in the 
corporate world. With machines openly available, security had 
to depend on the keys, which users kept secret. 


Another choice was having spare discs, all wired differently. 
In certain cases, it was possible to procure discs on special order, 
with wiring patterns different from all other discs manufactured. 
This meant that, even with the keys and a similar machine, an 
unauthorized person could not read the ciphers unless he 
managed to obtain one of the special rotors as well. 


There were also spare rotors available. This allowed even 
more complexity. With a five-rotor machine and five spares, 
there were 25 different combinations available even before 
starting with the keys. Knowing the cipher key wouldn’t help 
without also having the rotor key. 


A mechanical improvement was the “reflector,” which was a 
special contact plate at the end of the machine. Instead of taking 
off the current at the contact to feed it to a typewriter key, a 
wire would route it to another contact on the plate, to send it 
back through the rotors. Final take-off would be at the starting 
position, with the current having passed through the system of 
rotors twice. This gave the effect of ten rotors. 


The plug-board, located between the keyboard and the rotor 
system, was another wrinkle. There were wires and plugs that 
the operator could arrange according to different patterns, or 
keys. This changed the order in which the impulses started 
through the rotor system. Thus, the impulses went from the 
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keyboard through the plug-board, on through the rotor circuits, 
and finally to the printer (Figure 9). 


The plug-board was redundant. While it offered greater 
security, it was unnecessarily complex to operate. At least as 
much security would have been available with far less trouble 
by adding another rotor. 


KEYBOARD PLUG BOARD ROTORS PRINTER 


Figure 9 


Schematic of electric rotor cipher machine. 


The Enigma machine had two interesting features: reciprocity 
and exclusivity. The reciprocal feature meant that the machine 
would work exactly backward if required. Typing in an “A” 
pave a “D,” for example, but typing a “D” would give an “A.” 
l'his made deciphering easier. Exclusivity meant that the Enigma 
would never give the same letter as ciphertext for itself. Typing 
an “A” would never produce an “A.” 


Unfortunately, these features did not give extra security. The 
exclusivity feature limited the choices by 1/26 each time, and 
this made it easier for the code-breaker. The reciprocity feature 
made it easier for a poorly-trained operator to use. 


The first generation of cipher machines were primitive, of- 
(ering good security but poor convenience. The Enigma at first 
required two operators, one to read the message and a second 
\o work the machine. The enciphered message then had to go 
\o the communications room for transmission through regular 
channels. A later development was “on-line” encipherment. This 
simplifies the task for the operator, who types the message while 
the machine enciphers and transmits it simultaneously. The ad- 
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vantages are increased speed and convenience, and reduced 
errors. 


SOLID-STATE MACHINES 


The electro-mechanical machine is obsolete. Developments in 
integrated circuits and solid-state logic chips provide the 
opportunities for building all-electronic machines such as the 
“Cryptel,” which is about the size of a portable electric 
typewriter and contains a “modem” to transmit messages over 
telephone lines. 


SELF-DESTRUCT 


Capture of a modern cipher machine can be a national dis- 
aster, which is why governments take extreme steps to prevent 
it. Normally, these machines are in use only at heavily secured 
locations. In foreign embassies, they’re always behind locked 
doors at the interior of the building. There are enough walls and 
doors to delay an intruder long enough for the machines to be 
destroyed. 


The armed forces try to keep their cryptographic facilities in 
secure locations. On navy ships, the cipher room is always deep- 
ly buried inside the ship, behind a locked door. Traditionally, 
ships’ captains were under orders to throw the code books over- 
board if surrender was unavoidable. Today, this is unlikely, and 
the code room contains enough devices to destroy its contents 
in case of capture. Sometimes, this doesn’t work very well, as 
in the case of the U.S.S. Pueblo. 


The army tries to keep cipher facilities far enough behind the 
lines to be relatively safe. Still, there’s the possibility of a surprise 
attack, or a landing by paratroopers, and these facilities have 
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their own “bodyguards.” Cipher clerks are required to be armed, 
and one or more remains on duty 24 hours a day. 


All machines are equipped with self-destruction devices, 
usually consisting of an incendiary bomb within the “guts” of 
the machine. Pulling a red knob attached to a cord or wire drags 
4 piece of magnesium through an abrasive igniter, and this sets 
off the “thermite” mixture. The heat generated is enough to melt 
down the vital components within a few seconds. Because 
thermite carries its own oxygen, it can’t be put out with a fire 
extinguisher. Cipher machine operators are under standing 
orders to destroy the machine before retreating, even at the risk 
of their lives. 


SCRAMBLERS 


These are devices to make the human voice unintelligible to 
cavesdroppers. Scramblers in various forms have been in service 
for many decades. Indeed, a primitive scrambler was patented 
in 1881.3 This primitive device chopped the conversation into 
short fragments and routed them alternately over two different 
lines. 


Frequency inversion was the next step, and several commer- 
cial devices appeared during the 1920s. These simply invert the 
lrequencies of human speech, making the low frequencies come 
out high and vice versa. This gives the speech a whining, 
squealing quality which is harder to understand than unaltered 
speech. 

Band-splitting was the basis of the Bell System “A-3,” devised 
during the 1930s. This broke the speech up into bands, switched 
their frequencies, inverted them, and when used in conjunction 
with a radio-telephone, switched transmission frequencies every 
several seconds to make eavesdropping harder. 
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Although digital sound recording is commonly-available 
technology today, an early application, a couple of decades ago, 
was for voice privacy. Breaking speech up into digital “bits” 
allows enciphering in a way that’s absolutely unintelligible to 
anyone without digital equipment and the cipher key.4 This was 
originally called “PCM,” or Pulse Code Modulation, and it lends 
itself to rapid encipherment by a one-time or a pseudo-random 
generator. This technique is pretty well established now. It’s 
been advertised in technical and military magazines for a couple 
of decades. 
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Transposition Ciphers 


The other major type of cipher is the transposition cipher. In 
(his, there is one or more ways of mixing up the order of the 
letters to make the message unreadable. Let’s look at a few 
‘imple transposition ciphers quickly, before getting on to the 
professional-grade ciphers. 


THE RECTANGLE 


One of the simplest ways of enciphering a short message is 
(0 write it in several lines: 


COMEAT 
ONCEIN 
EEDYOU 
RIGHTN 
OWXXXX 


We then re-write the message by rows: 
COERO ONEIW MCDGX EEYHX AIOTX TNUNX 
This appears quite unintelligible, but the simplicity of the 
ystem makes it unlikely to hold up a code-breaker very long. 
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This also makes it easy for the sender to encipher his message. 
There’s no complicated key to memorize. 


A problem with this type of cipher is that capacity is limited. 
We could choose a larger rectangle, such as one with 48 places. 
This factors out to 6 x 8 or 4 x 12. The message doesn’t have 
to come exactly to 48 letters, as we can fill empty spaces with 
nulls. The largest practical size is 72 places. This factors out to 
10 combinations. 


There’s no reason why more than one rectangle can’t be used 
if the message is longer than the capacity of one. For simplicity, 
it’s just as easy to use two 36-letter patterns as it is to make one 
large 72-letter one. There’s actually no advantage to one or the 
other regarding security. 


THE RAIL FENCE CIPHER 


Figure 10 


Using the rail fence cipher, 
a message is divided and rewritten. 


In this simple system, we write the message horizontally, in 
several long rows, as shown in Figure 10. Once we’ve divided 
the message into segments with diagonal slashes, we re-write it, 
starting from the extreme bottom left: 
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AOTYR ECORF OUOOM RWREI WMAGI ETHLX 
OTLXN ABXCW EXEAT XIYOX NTOXE OLEMD 


Deciphering involves arranging the letters in diagonals.! 


GRILLS 


A grill is a template, a piece of paper or cardboard with 
\quares or rectangular slots designed to fit over a standard sheet 
of paper. The sender writes his message in the slots, removes the 
grill, and fills in the rest of the sheet, constructing words as best 
he can. A more ingenious grill is called the “Cardano Grill,” 
after the Italian who invented it. This is a rotating grill with 36 
places, only nine of which are cut out. It is shown in Figure 11. 


Figure 11 
The Cardano Grill. 


Note that this grill has a pivot hole in the center. The sender 
begins his message following the numbered holes, then rotates 
the grill 90 degrees, using a pin through the pivot hole. The cut- 
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outs now are lined up on nine fresh places on the paper, allowing 
another nine letters. Now the writer rotates the grill again, writes 
another nine letters, and repeats the cycle. 

This sort of cipher provides more security than a geometric 
one for short messages. It doesn’t take much time or ingenuity 
to take a message of 25 or 36 letters and to try it in several 
arrangements. Arranging the letters in a square or rectangle 
allows reading up or down, backwards, forward, and diagonally. 
The Cardano Grill, while not impenetrable, is harder to dope 
out. 


ADFGX 


At times it’s possible to gain good security by combining a 
simple substitution with a simple transposition cipher. One of 
the most successful was “ADFGX,” the German WWI cipher. 
The substitution cipher turns letters into digraphs, using a grid 
and only five cipher letters: 


a dfg x 
a C Y UM V 
d DJ FSN 
f B QR LW 
g GEHOA 
x PZKXT 


Having only 25 spaces meant that it was necessary to drop 
one letter. In this case, “I” is missing, with “J” taking its place 
when necessary. To encipher, we find the letter in the grid, and 
start with the cipher letter at the left, then the one at the top, 
for the digraph. “Y” becomes “ad.” Now let’s encipher our usual 
message: 


I NEED YOU COME AT ONCE 
dd dxgdgdda adggaf aaggaged xxx ggdxaagd 
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The next step is to write the message itself in grid form, and 
(o number each column according to a memorized key:? 


1987463520 
dddxgdgdda 
adddafaagg 
aggegexxxges 
dxaagd 


The “O” stands for “10.” We then take each column in 
‘iumerical order to write out the message: 


daadd gggax gaged axdfx dxgda dggad dgxag g 


One problem with this cipher is that the last group consists 
of only one letter. Adding nulls consisting of letters such as 
‘udfgx” would confuse the addressee because they’d interfere 
with the transposition order in the deciphering. Using other 
letters would stand out and tell a code-breaker exactly which 
letters were nulls. 

The Germans later brought out a second-generation mixed 
\ipher “ADFGVX.” This built upon a grid of 36 characters, and 
included numbers: 


adfgv x 
aC 15UMV 
qdDJIF2s N 
f B9RL3W 
g¢ 4GE8sas:O0A 
v TY 7HQ 0 
sPZKX61 


Note that this restores the letter “I,” as well as adding the 
lipits “1-0.” 
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“ADFGVX” was a very successful field cipher because it wii 
truly hard to crack. The French cryptanalysts never broke mor 
than a few keys, and these only during heavy traffic days.* 

“ADFGVX” was vulnerable, however. The problems with 11 
were that the Germans sent identical messages to differen 
headquarters, and that the digraphs gave frequency counts thi! 
were definitely monoalphabetic. 
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Codes 


A “code,” as we’ve seen, is a crypto-system in which we 
‘eplace entire words or phrases with code words, groups, or 
iiimbers. Because there’s no statistical relationship between 
‘leartext words and phrases and their code equivalents, breaking 
a code is much harder. Also, because there’s no internal 
‘onsistency between letter and number groups, and no logical 
jogressions, a code-breaker who obtains a coded message and 
iis cleartext together doesn’t have a lever to pry loose the rest 
ol the code. 


Let’s look at the various types of codes, their make-up, and 
(lifferent applications. 


MILITARY CODE NAMES 


Military services maintain lists of code words to assign to 
pecific military operations, place-names, and equipment. A 
\ypical list of military code words contains terms such as these: 
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AMBER MOUNTAIN 
BAKER NEBULA 
CHARLIE ORANGE 
DELTA PRESTO 
EGGPLANT ROBERTS 
FIREFLY SHOTGUN 
GIANT TAILOR 
GOLD URANUS 
HORNET VOTER 
INTACT YELLOW 
JERSEY ZERO 


Code words of this sort may be nouns, verbs, adjectives o1 
anything else, as long as they don’t suggest what they represent. 
Lists of code words not yet chosen go to various military 
commands, with care not to duplicate code words between lists. 
Commanders choose code words to denote various plans, 
projects, and objectives, and discard the code word once the 
operation is over. 


COMMERCIAL CODES 


These were originally called “telegraph codes,” because they 
were devised to save transmission time and costs for their users. 
The first of these came about in the late Eighteenth Century 
when a commercial semaphore system made its debut in 
France.! With the invention of the telegraph, many other codes 
appeared. The main design points for compilers of commercial 
codes were to minimize errors by not making the code words 
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(00 similar and open to confusion, and to pack as much meaning 
as possible into a single word. 


Dictionary words were liable to misspelling if the telegrapher 
dropped a single dot or dash, and code compilers compensated 
lor this by creating artificial code words, groups of syllables with 
no other meaning. These were designed only for error-free 
transmission.” 


LETTERS OR NUMBERS 


In designing a code, the basic question is whether code words 
shall be letters or digits. Letters have the advantage that they can 
form pronounceable words, for verbal transmission. Numbers, 
on the other hand, lend themselves very well to “super- 
encipherment.” This means enciphering the code groups for 
extra security. 

Whether one or the other, custom is to list code groups of five 
characters, with their meanings, in two sections. The first is for 
encoding, and lists the meanings alphabetically. The decoding 
section lists the code groups in order. 


Why five characters? With all of the permutations possible 
with 26 letters in the alphabet, about eleven million combina- 
lions are possible. With only ten digits possible, 1 through 0, 
we’re down to 100,000 combinations, but these will still cover 
more than enough for most purposes. 


THE DICTIONARY CODE 


A simple way of constructing a code for general use is to seek 
the words in a pocket dictionary and write the number of the 
page, and the number of the word on the page. This results in 
a five-digit group. 
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Page 1 would register as “001,” Page 2 would be“002,” et 
Few, if any, pocket dictionaries have more than 999 pages, sv 
three digits suffice. Likewise, few pocket dictionaries have morc 
than 99 words on a page. 


A pocket dictionary is desirable because, for our purposes, we 
only need the listing of the word. A detailed definition, with 
etymology, etc., is unnecessary and takes up space. 


There’s one problem with using a dictionary code. Certain 
common words, such as THE, AND, AN, IT, TO, etc., will 
repeat often, always with the same code group. One way to 
solve this problem is to use a second paperback book to 
supplement the dictionary. The second book may be a novel 0: 
non-fiction. Whatever the subject, it’s likely to have words in 
their normal distribution in the language. These will serve as 
“spares” for encoding to foil a code-breaker. Whenever : 
common word turns up, we find it in the spare book and write 
the page and word number. To differentiate between the two 
books, we use a five-digit number for the dictionary and a six 
digit one for the spare book. We'll need the extra digit because 
there are usually more than 99 words on a page in a novel 01 
non-fiction book. Because they’re common words, we'll have no 
trouble finding them when we need them. 


An observant code-breaker might guess that, because some 
code groups begin with one or more zeros, they refer to pages, 
and he might guess that this is a dictionary code. The way to 
counter that, super-encipherment, also adds extra security. A 
quick and dirty way to do it is to add today’s date to each num- 
ber. 


Let’s say that today’s date is October 6, 1988. We write it as 
10/6/88 and add 10688 to each five-digit group. If the group 
has six digits, we use a zero before the 6: 10/06/88, and add 
100688, using non-carrying addition. The weakness here is that 
the same super-encipherment goes on every group. If the code. 
cracker can dope out one or two groups, and realize that a date 
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is the super-encipherment, he’Il be able to strip it off every group. 
(nce into the code, he’ll progressively be able to figure out the 
incanings of more groups. Worse, he’ll realize that the superenci- 
pherment is based on a date, and this will give him a head start 
with future messages. 


A better way is adding a list of random numbers to each digit 
in the code groups. This will disguise the occurrence of zeros and 
make it doubly difficult to make progress on unlocking the code, 
even if a lucky event allows the code-cracker to break into the 
code. Even if he obtains an entire message in clear, he won’t 
know what all of the other groups mean because of the random 
iiumber super-encipherment. 


A convenient way to obtain random numbers is to use the 
pages of the second book. Converting the letters to their 
alphabetical numbers will provide a long list of digits for super- 
encipherment. A=1, B=2, etc. It’s also possible to number the 
letters backwards, for slight extra security.2 There must, 
however, be a system to advise the addressee on which page to 
begin. The simplest is to use pages in sequence, omitting title 
pages within the book. Another is to begin each message with 
au code group that gives the page number, such as “00015.” 


When super-enciphering, it’s important not to repeat the 
random numbers. A code-breaker who notices that the first 
groups of several different messages are the same may decide to 
stack them in columns and start subtracting each group from the 
others in the same column, which will reveal factors they have 
in common. This can provide an entry into the actual code 
proups.4 


DISGUISING THE CODE 


The logical assumption, when confronted with five-letter 
yroups, is that if they’re code groups, they'll be random letters. 
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A frequency count will show a random pattern. One way «| 
causing a code-breaker grief is to use code groups that show 1 
normal or near-normal frequency count. This may sucker him 
into trying various transposition permutations. 

Another way is to use a frequency distribution, but on tli 
wrong letters. Instead of using “E” as the most common, we can 
use “Z,” for example. 


THE HOME COMPUTER 


We won’t spend much time on this, as not everyone has 3 
home computer. We'll also have to be very general, because th 
various computer programs operate with different commands 
Creating a code book quickly and economically with a home 
computer requires a database program and a word processiny 
program. The steps are: 

Bring the word processing program’s spelling check: 
dictionary into an open file. Edit it, deleting unnecessary word: 
and adding needed phrases. Store this. 

Start another file with the word processing program, ani 
“read” the list of words into it. Generate a random list of code 
groups, numbers or letters, placing them before the dictionary 
words and phrases. This will be the encoding part. Print this out 
The only inconvenience in using this part will be that the second 
column, containing the meanings, will be alphabetized instea| 
of the first. 

Copy this file, and use the “sort” function of the databasv 
program to re-arrange the code groups in order. This will then 
be the decoding part. Print this out. 


SECURITY 


Codes offer the best security. Because they deal with messayc 
elements that are much harder to tabulate statistically, normal 
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methods of cryptanalysis don’t work well with them. Adding a 
super-encipherment creates a tangle so dense that most often the 
code-cracker’s only hope is to steal the code. 


SOURCES 


|. The Code-Breakers, David Kahn, NY, MacMillan, 1967, p. 
836. 


2, Ibid. pp. 839-842. 


‘. Secret Warfare: The Battle of Codes and Ciphers, Bruce 
Norman, NY, Dorset Press, 1973, pp. 146-147. 


4. The Code-Breakers, pp. 441-443. 
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8 
Code-Breaking 


This is a difficult subject to follow, because it’s deeply buried 
in secrecy. While we see much material published about 
techniques of code-making, the other process, code-breaking, is 
almost ignored. There are a few books written by amateur 
cryptanalysts, such as Gaines,! and a few others dealing with 
war-time code-cracking. The Gaines book is for code and cipher 
hobbyists. The others are about real-life, heavy duty code- 
cracking. One such is The Broken Seal, by Ladislas Farago.? 
This deals with the cracking of the Japanese diplomatic code, 
which gave a last-minute warning of the Pearl Harbor attack. 
Another is The Ultra Secret, which gives a sketchy account of 
how the British made use of Enigma intercepts. Most of these 
books appeared decades after the events they describe, and were 
heavily censored. 


There’s a reason for this, of course. Those with experience in 
government code-breaking are usually enjoined from publicizing 
anything about their work. The little that comes out is heavily 
censored to avoid giving an actual or potential enemy clues 
about current efforts and capabilities. An example is the 
revelation of the “bombe,” the British code-breaking computer 
of the early 1940s. This machine, which they inherited from 
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Polish code-breakers, was long obsolete before British autho: 
ities allowed a public word to appear. 


Cryptanalysis, or code-breaking, is usually the most secret ! 
all government activities. It’s more closely held than the codes 
the government uses. Governments admit they use codes ani 
ciphers for their military and diplomatic traffic, and only classi, 
technical information about the systems themselves. 


However, all governments deny even attempting to read othe: 
nations’ encrypted traffic. Any sort of eavesdropping is almos! 
always a deep and dark secret. There’s a very clear and obvious 
reason for this. A government which can read another’s “mail” 
has a superb advantage in planning, negotiation, and overall 
competition. Knowing what an enemy, rival, or ally is thinkiny 
and planning provides an edge which can quickly disappeai 
once the rival government becomes aware that its communica 
tions aren’t secure. This is why NSA, the National Security 
Agency, stays out of the public eye most of the time. 


Most of the NSA’s activity is aimed at decrypting othe: 
nations’ communications, and NSA officials apparently feel that 
the less said about this, the better. This attitude isn’t unusual. No 
nation admits publicly that it reads the codes of other nations 
with which it is not at war. 


Nations spy upon all three: enemies, rivals, and allies. The 
reason for spying upon an enemy is obvious. A rival may be an 
economic rival, and knowing future trade plans enables makiny 
counter-moves to secure a trade advantage. Reading an ally’s 
communications helps determine if the ally is operating in good 
faith. One of the nightmares that belligerents have in any alliance 
is that one or more members will break away and sign a separate 
peace, as Italy did from Germany in 1943. Warring powers will 
make almost any concession to keep an ally in the fight, as the 
United States did to keep the Soviets fighting during World Wa: 
Il. 
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Naturally, revealing that one spies upon an ally promotes dis- 
trust, which is why this is always undercover. When William 
Hamilton Martin and Bernon Ferguson Mitchell, two National 
Security Agency employees, defected to Soviet Russia in 1960, 
they revealed that their employer was reading the codes of our 
allies. This caused extreme embarrassment for the United States, 
which is why the Soviets were eager for Martin and Mitchell to 
tell all at a press conference. 


This secretiveness makes more difficult the task of separating 
fact from fiction. On one hand, we have seen a rash of books 
on the theme of “How I Won The War By Code-breaking.” 
I'hese tell how the hero saved his country untold hardship by 
his force of intellect, relentlessly struggling to tease apart the 
secrets of the enemy’s crypto-system. On the other hand, we see 
accounts such as the one by General Cesare Ame, head of Italian 
Military Intelligence during WWII. He relates how his agents 
stole the American “Black” code from the American Embassy 
in Rome, and with this his office and the Germans were able 
\o read messages sent by the American military attache in Cairo, 
(‘olonel Bonner Fellers. The Italians were able to obtain the 
American Black Code undetected because two embassy 
employees were Italian nationals in the pay of the secrét service.* 


Colonel Fellers was no ordinary military attache. He loved his 
job, and he passed on to his headquarters in Washington every 
detail he could pick up regarding British military dispositions 
und plans in the Western Desert. The intercepts gave the Italians 
vital information about British moves. They passed on the 
messages to their German allies, but did not hand over the entire 
purloined code. The alliance was not very solid, and there was 
mutual distrust and rivalry. 


The Germans, with some decoded messages in hand courtesy 
of their Italian allies, had a head start at breaking into the 
“Black” Code. Black was a regular code with a “super- 
encipherment” added. The cipher clerk added a fixed number 
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to each code group, and this made it harder to break the code 
The key number changed regularly, probably daily, and this 
avoided giving an eavesdropper a large enough sample of groups 
to get a break mathematically. However, the Germans had noted 
that the messages always began with the same salutation 
codegroup, and this allowed them to find the key number at the 
outset, and use it to unlock the rest of the message. 


Probably every secret service in the world has experts al 
breaking and entering. This is known, in American slang, as « 
“black bag job.” In Italy, the Carabinieri was in charge of these 
activities. The Carabinieri is the national police, roughly 
equivalent to the American FBI, which also does black bag jobs 
In Britain, the “Security Service” carries out breaking and en 
tering, and warrantless searches.> 


Purloining codes is a highly specialized skill. More important 
than obtaining the code is doing it quietly, without detection. I! 
the burglary victim discovers that his code’s no longer secure, 
he’ll change it, negating the entire effort. One attempt involve: 
“bugging” the Soviet Embassy in Ottawa. In this case, agents o! 
the Royal Canadian Mounted Police and Britain’s MI-S installed 
microphones in various rooms, but the Russians apparently 
knew of the bugging and moved their secret activities to another 
part of the building.® 


There’s another effect of code-breaking, of interest mainly to 
propagandists and historians. During WWII, many highly 
acclaimed military leaders owed their successes to code 
breaking, which revealed to them the enemy’s plans. Germany's 
General Rommel did so well with his Afrika Korps because he 
knew the British moves in advance. The American General 
George Patton had regular transcripts of important German 
messages to help him in his planning. Reputations that seemei| 
so bright become duller in the light of new information. 
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SKILL OR LUCK? 


Amateur code-makers sometimes devise codes or ciphers they 
think are unbreakable, but actually are surprisingly easy to 
crack. However, a reasonably competent cryptographer can 
devise a code or cipher that will resist analysis for months or 
years. As we’ve already seen, various crypto-systems of the 
major powers remained secure until an enemy obtained a copy 
of the code or the enciphering machine. 


No doubt, there were brilliant code-crackers, but often a cer- 
tain amount of luck figured into it. Often, a code-breaker obtains 
an edge which provides an insight into how the code or cipher 
works, and a key to unraveling it. Breaking into a competently 
devised crypto-system is so difficult, and takes so much time, 
that governments make serious efforts to find short-cuts, such as 
stealing other nations’ crypto-systems. Not all are lucky enough 
to have a code book delivered into their hands by the black bag 
squad, but sometimes a lucky accident brings it to them. 


In 1914 the German cruiser Magdeburg sank after an engage- 
ment with Russian ships, and the Russians obtained its code 
books. Unsure of what to do with them, the Russians passed the 
precious books to their British allies, who knew exactly what to 
do with them. As Germany’s chief naval rival, the Royal Navy 
had a burning interest in cracking German codes and ciphers, 
and capture of the German code books gave the code-breaking 
office a flying start. 


Breaking into the new German electro-mechanical crypto- 
system, the Enigma, was not as difficult as some authors made 
it out to be. It wasn’t a matter of discovering a pattern in a totally 
unfamiliar system of digits. Allied code-crackers had a “crib.” 
Actually the rotor cipher machine had been invented in three 
different countries by four different men between 1915-1925, 
and there were commercial versions commonly available. The 
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German military models were more complex, but Allied code- 
breakers had their vital lead provided by the commercial models 
purchased over-the-counter. In another case, a German sold 
secrets of the Enigma to French Intelligence. Once aware of the 
basic layout, it was logical to deduce the improvements which 
would make the machine cipher more secure. From this, 
securing the keys, which often changed daily, was another 
problem which the code-crackers solved in a short time. 


In May, 1941, the British captured a German submarine, the 
U-110. The crew failed to throw the code books and the Enigma 
machine overboard, and this gave British cryptanalysts a clear 
view at the German naval code because they now had the keys 
for the next several months.’ Previously, British naval units had 
captured the extra rotors and the current keys from a disabled 
German submarine, but this wasn’t enough to give them the 
entire system on a plate. 


Defectors sometimes bring tangible help for the code- 
breakers. When cipher clerk Igor Gouzenko defected from the 
Soviet Embassy in Ottawa in 1945, he brought with him a batch 
of secret telegrams as his “admission ticket.”® These messages 
not only provided vital information for Western intelligence 
agencies, but allowed a comparison between encoded versions 
and cleartext. This is a vital step in code-cracking, and enabled 
reading Soviet coded traffic for several years back. 


Another instance of code-cracking that was top-secret for 
forty years was that involving the “Finnish code book.” During 
WWI, the Finnish military had captured a Soviet code book 
that had been partly burned. The American OSS had managed 
to acquire a good part of this through some sub-rosa transactions 
with the Finns. A bizarre sequel to this event was that the 
Secretary of State, Edward Stetinius, protested to President 
Roosevelt that reading our allies’ codes was dirty pool. The 
President ordered the OSS to return the material to the Soviets. 
It’s almost certain that, before handing it over, OSS officers 
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photostated it. We don’t find any admission of this in the source 
material, though.® The author admits that there are certain as- 
pects of the affair that the National Security Agency has insisted 
remain secret to this day.!° What has come to light, however, 
is that these decoded messages led to the uncovering of Burgess 
and MacLean, Harry Gold, and the Rosenbergs. We can also 
infer that information obtained from Igor Gouzenko helped in 
the effort, because Soviet officials under diplomatic cover in 
Canada had a very hot espionage operation running during the 
Second World War. In keeping with a well-known practice of 
running an espionage operation from a neighboring country, 
Soviet spymasters seeking American nuclear bomb secrets 
operated in both Canada and Mexico. 


CRIBS AND PATTERNS 


There are many ways in which a code-cracker can make a 
start in breaking into a crypto-system. Let’s consider the cribs 
first, as these often provide the breakthrough that a technician 
needs. 

Many messages contain stereotyped language, such as 
addresses, salutations, boilerplate wording, etc. A code-cracker, 
who knows the forms that the target messages take, can dope 
out that the first few code groups stand for certain meanings and 
names. For example, a message sent in the military top-secret 
cipher may start with: 


PRIORITY ONE 

ATT: FIRST ARMY HEADQUARTERS 
COMMANDING OFFICER 

EYES ONLY 


If these lines begin every message, they provide an entry into 
the crypto-system. Today’s code clerks are fairly sophisticated, 
and know how to defeat this. A good way is to break the 
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message in half, and put the second half first. This avoids 
stereotyped beginnings. The decoding clerk can put the message 
in order after decrypting. 


Another clue is the use of place-names and other propci 
nouns. If, for example, a diplomatic conference deals with A| 
sace-Lorraine, it’s a simple deduction that the place-name will 
be somewhere in the text. So will names of towns and geo 
graphic features in the area in question. Names of delegates may 
also form part of the message. Military traffic contains many 
place-names during active operations, and these serve as cribs for 
the code-breaker. This is why a cryptanalyst will always want 
to know the context of a message before starting his work. 


Another crib is the known message. If the Secretary of State 
hands a foreign ambassador a message to transmit to his 
government, code-crackers can expect that the embassy will be 
transmitting it very soon. With the cleartext, they can pry the 
code loose. Again, sophisticated code clerks know how to 
counter this. They paraphrase the message before encoding it, to 
prevent a direct cleartext-ciphertext comparison. 


A variation on the theme of the known message is the forced 
message. During the months after Pearl Harbor, American navy 
cryptanalysts were reading the Japanese naval code, JN-25 
They understood enough of the code to make out that the 
Japanese were planning an important operation in the near 
future. However, this code also included some code notations 
within it, obviously for brevity. One was the designation “AF,” 
the place against which the forthcoming operation would take 
place. American code-crackers were unsure of its meaning, but 
suspected that it meant “Midway.” To confirm this, they “plant. 
ed” a piece of disinformation, sending a message in a low-grade 
cipher that Midway Island was short of water. They knew that 
the Japanese code-crackers could read this cipher, and waited 
for the reaction. Soon a Japanese message stated that “AF” was 
short of water.!! 
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Sometimes sheer dumb luck provides a way in. A clerk trans- 
mits a message in the high-security code or cipher, and receives 
a reply that the equipment at the receiving end is temporarily 
out of service. The clerk then sends the same message in another 
cipher. This provides an entry into both for the codebreaker. 


The technique of operation sometimes carries with it a way 
in for the enemy code-breaker. Rotor machine ciphers, for 
example, require keys for the initial rotor settings. These are 
often compiled and issued to field units months in advance of 
their use. Warships, for example, need keys for every day they’re 
at sea, and have to carry them aboard. Another weakness is that 
some rotor machines also use a separate key for each message, 
as well as the day’s key. Common practice is to provide this key 
at the beginning of the message, repeating it to be sure that the 
recipient gets it. An eavesdropper who understands this gains a 
head start in breaking into the machine cipher. 


For tight security, it’s common to change the keys every day. 
This means that there are very many keys in circulation. The 
more keys there are, the less dissimilar they can be. Sometimes, 
after a crypto-system’s been in use for several years, we may find 
some keys only a few positions apart. With so many keys, some 
messages will overlap, giving an access with mathematical 
analysis. 

In other cases, the system brings with it the prospect of human 
error. A cipher clerk may send a message in the previous day’s 
key, then catch his error and repeat it with the current key. This 
provides the code-breaker with a good opening. In other in- 
stances, different units will get the same orders, with only the 
addresses and salutations different. Both cases provide the code- 
breaker with the same plaintext, and comparing the two 
messages can give a quick insight into the encryption method 
used. There’s still need for technical analysis, but the security 
lapse makes the task easier. 
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CODE-BREAKING TECHNOLOGY 


Code-breaking doesn’t usually take a climactic form. We 
don’t see hours of frustrating work, with the crypto text suddenly 
giving up its secret at the end. More often, especially with 
complicated codes and ciphers, the work is slow, and proceeds 
only by increments. Statistical analysis will reveal a pattern, but 
this will result in only a few elements of the message coming out 
The technician must then poke and probe, trying various com 
binations, slowly teasing the message out letter by letter. 


To break into an unknown message by cryptanalysis, it’s 
necessary to find out how it was encrypted. The first step is to 
determine if the message is in code or cipher. This can be the 
most difficult part, because only the most simple-minded code 
makers would produce an easily recognizable message. Let’s 
look at a very simple message: 


SDD NHGY FTG NKJKLHJ DRR 


It’s obvious that this is a substitution cipher. The different 
word lengths are the tip-off. On the other hand, if we sec 
something like the following, we know that it’s likely to be a 
transposition cipher: 


SDFGHJKL 
WERDFCVB 
YUHJJIKNM 
LKJHGFFD 
IUYTREWQ 


The block of letters is composed of five groups of eight letters 
each, and no code has eight-letter groups. There’s simply no 
need. 
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Simple codes, if there’s no attempt to disguise them, are in 
groups of five or six letters or numbers: 


GHJKL RTYEW XCVBN GHJKL JHGFD FDSAW RFVGT YHNJU IKMJU IKUYH 


There’s no reason why the user of a transposition cipher can’t 
break his message up into five-letter groups. A code-cracker can 
spend many frustrating hours trying to figure out the system 
without gaining an insight into the type used. 

As we’ve seen, a cryptographer who wants to cause his rivals 
grief can superencipher his code groups. 


The next step in technical code-cracking is to make a 
frequency count of the letters. We know that the most common 
letters in English are, in descending order of frequency: 


ETAONRISH 


The frequency count is, however, a statistical tool. What it 
means is that the longer the message, the better the odds of its 
frequency distribution being normal. Short messages can give 
trouble. Let’s look at one which fits the rules: 


COME HERE AT ONCE 


This message has 4 “E”s, which is normal in the sense that 
“E” is the most common letter in English. Another short 
message might read: 


DON’T COME NOW 


In this one, there are three “O”s and only one “E.” This 
throws off the usefulness of the frequency count. 
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For best results, we need a fairly long message, or several 11 
the same cipher. Assuming the language is English, we'll gc! 
something like this if it’s a simple transposition cipher: 


- 618 
- 475 
- 400 
- 398 
332 
- 348 
- 320 
- 299 
- 248 


DAeAZOPrHm 


This is a distribution frequency that follows the actual 
occurrence of these letters in English very closely. A safe move 
is now to try to dope out the pattern of transposition. This 1s 
often a lot of trial-and-error. 


If it’s a simple substitution cipher, we'll get a similar frequency 
distribution, but not for the same letters. Instead, it might look 
like this: 


- 618 
- 475 
- 400 
- 398 
fe I 
- 348 
- 320 
- 299 
- 248 


DAGNKTSOAXK 
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With such a distribution, a good starting point is to assume 
that “X” stands for “E,” “G” stands for “T,” etc. 


There’s another possibility. The cipher might be designed to 
suppress frequencies, as is the case with a polyalphabetical 
cipher. Then, the results might look like this: 


- 418 
- 460 
- 401 
- 375 
365 
- 368 
- 370 
- 399 
- 348 


DANK OF SOM 


This is a headache, because it suggests a polyalphabetic 
cipher. However, there is a way to crack this type of cipher. This 
is called the “Kasiski” method, named after a German officer 
who devised it in the middle of the Nineteenth Century. Let’s 
look at a simple example: 


Key: LOVELOVELOVELOVELOVELOVELOVELOVE 
LOVELOVELOVELOVELOVELOVELOVE 


lext: Thereisanotherproblemthatweshouldthinkaboutthistime- 
thatwehave 


UGQMGFCAXZBWGWFEMWNJZYUNERRQLDZASIUNVXD 
VDWTBKDFCKCBQKDOBHGGVI 


We see recurring patterns, such as “FC,” “KD,” and “UN.” 
Working with these can give us the length of the key. The 
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period, or separation, between the two instances of “FC” is 40 
If we factor that, we get 5 and 8, and 4 and 10. The next onc 
to analyze and factor is “UN.” This gives us 12, which break; 
down into 4 and 3. “KD” gives us 12 again, with the samc 
factors. We find that “4” is the only factor common to all three, 
and therefore it’s the most probable. It’s not the only possibility, 
as the key word might have been one which has repetitions in 
it, such as “ONION.” That would give some false leads to the 
length of the key word, but a little trial-and-error would reveal 
the true length. 


Once we know the length of the key word, we know how 
many different ciphers are in the message, and we have to solve 
it remembering that only every fourth letter is in a particulai 
substitution cipher. A practical point is that this cuts the samplc 
size down to one-fourth, and this is why we need more text to 
construct an adequate frequency table. With a frequency table 
for each cipher, we can make some trial substitutions and start 
cracking the system. 


One type of solution to the polyalphabetic cipher is called the 
““Kerckhoffs,” after its inventor. The main value of the 
Kerckhoffs method is that it doesn’t matter how long the key 
is. The technrque is to stack several different messages 
enciphered with the same key. The result looks somewhat like 
the example on page 85. 


No matter what the key is, or how long it is, the first lettc: 
in each row has been enciphered with the same cipher alphabet 
This simplifies the problem, because it means we can treat each 
column as a simple monoalphabetical substitution. As a practical 
matter, we can soon find several columns enciphered with thc 
same alphabet, because few key words run over 12 letters. 


LKJHGFFDPOI JHGFBVXSREWREQRFDCWEDFVYFDZRTYJMUHGVCTYUJIUYTREWQ 


QSXEDFVRFAZASZXEDEDRDFCRFEDUJKWSUJRDFCOLYHGFCPKJYIYGGOJFJFUF 
EDGWFDJHJHVBTFDEFIJHUHGVYGEDIK JMWAI JMESGBNGFDYHKWYDHS JDGHDSH 


SDFGHJKLWERDFCVBYUHJ JKNMCGYNJ J WEEDCRFVYHJUJKUIKOLOLPLPTYHJNM 
YHJTFYHNTFDGBNVCXVBNMBVCXZVBDS GHJKREYUJKRFDYHEDIKEDIDJDUJIOW 
WQQWESADFGSUJDSYHJIFTYCBNSYHJSLWPISOKDOKDIUJSYHNESUJDILWSHUJS 
ESYHI JRFDYHRFDSUHNGFDUHJNMHGFCOLGFPLYHGPLYGKKJSDBNMXHHGJHSSH 
DJHEUEUYBCABKJHSDGAYUIBHJVCGAR YUBVNMCBHJKHGSHIUGWSAPHJSTRGSS 


UGQMGFCAXZBWGWFMWN J ZYUNERRQLDZAS IUNVXDVDWTBKDFCKCBQKDOBHGGVI 


WIGS POUABNXZDFBKDWSAISFDJHKEWR YUFDKSGAHJDASSSDHJSDAFNBAHJ SDH 
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There’s another Kerckhoffs principle which can apply to 
alphabets derived with a keyword as a “primer.” Let’s look at 
an example of several such alphabets: 


COMPANYBDEFGHIJKLOQRSTUVWXZ 
OMPANYBDEFGHIJKLOQRSTUVWXZC 
MPANYBDEFGHIJKLOQRSTUVWXZCO 
PANYBDEFGHIJKLOQRSTUVWXZCOM 
ANYBDEFGHIJKLOQRSTUVWXZCOMP 


We see that in each alphabet, each ciphertext letter is 
separated from the other by a spacing which does not change 
between different alphabets. For example, there are two letters 
between “A” and “B” in all of them. Likewise, we find three 
letters between “Q” and “U” in all of them. This provides a 
tremendous break for the cryptanalyst. When he starts working 
out a solution for one cipher, he’s got a lead to the spacing on 
all of the others. This is what Kerckhoffs called “symmetry of 
position.”!2 We can take warning from this in constructing our 
own ciphers. A randomly mixed alphabet, different for each 
cipher, will defeat the Kerckhoffs technique. 


Yet another technique is laying out the message and writing 
the plain alphabets underneath it. This will bring out a message 
enciphered in a monoalphabetic or a polyalphabetic substitution, 
as long as it’s enciphered in coherent alphabets.!? Let’s see how 
one message might come out. 


RWNNMHXDLXVNJCXWLN 


This is our ciphertext. We write it out and complete the 


alphabets below it: 
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OZEZmMA+HDTODMMOIOMPPNKM 


HvOAZZrAH' =DOMMOASPnNKKXS SK CHaUnD 
<CHYFOH VO: ZEMAGHKTDOAMMOAOOPNKKS 
ZSrAeHMOM MONMPPENKKSSCHNDROVOZ 
SrAeH DOD MONPPENKKESSCHMNDROVOZ 
PACH TOMNM: DOWFNKKXSSCHUROVOZE 
OUMODARPPN: ~K SK CHNDAOVOAZZOCAGHe 
GCHNAPAHVOAZ: FHA DTOMmMIAPENKKSK 


SK CHNAOV' OCOAZZMA4HTDMOADMIOOSPNK 
SrAHH MOD MONPPNKKS SK CHNDOVOZ 


BHBAMOnMMOADM' FNKXKXSSKCHNROVOZZrAU 
DrFNKKXSSC' ANAHVOANAYyLZMK AGH DOA DMIO 
S<CHMNAPOV' OAZZMAGHDOMMIATrPNKM 


AH MOnMNMO' AMDEFNKMESESCHNROVOZZEH 


Ao MOMUMO' AODPNKXKSKCHUNUNROVOZZM 
SrAeH DOD MONTPPNKMSSCHNZDOVOZ 


ARPPFNKKXS KS ' GCHYURAOVOAZMAGH DBO MS 


SscHuwroOw: 


The message becomes very clear on one line. Note, however, 
that there are other words formed on various lines. We find 
“PULL” on the next to the bottom line, as we find “DIZZY” 
on the fifth line above the message and “OFF” on the line right 
below it. We know that the message is solved when we see 
coherent text all the way across, though. Single words don’t 
count. 
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There are also other methods of analysis. At this point, let’s 
introduce the paper slide, because we have to face the possibility 
that the cipher we’re trying to break is a transposition cipher, 
and the slide is useful against either type. The slide means writing 
the unknown ciphertext onto strips of paper which we can place 
against each other in different positions. This is a trial-and-erro: 
method, but if we see a word emerge while we're sliding the 
paper strips, we know that we’ve got a break into a transposition 
cipher. We can also use the paper slide with the letters of the 
alphabet in order, to work the deciphering procedure outlined 
above. 


THE KAPPA TEST 


UGQMGFCAXZBWGWFMWNJZYUNERRQLDZASI UNVXDVDWTBKDFCKCBQKDOBHGGV I 


SDF GHIKLWERDFCVBYUHJ JKNMCGYNJJWEEDCRFVYHJUJKUIKOLOLPLPTYHINM 


LKJHGFFDPOI JHGFBVXSREWREQRFDCWEDFVYFDZRTY JIMUHGVCTYUJIUYTREWQ 


QSXEDFVRFAZASZXEDEDRDFCRFEDUJKWSUJRDFCOLYHGFCPKJYIYGGIJFJFUF 


YHUTFYHNTFDGBNVCXVBNMBVCXZV BDSGHJIKREYUJKRFDYHEDIKEDIDHDUJIOW 


WQQWESADFGSUJDSYHIFTYCBNSYHJSLWPISOKDOKDIUJSYHNESUJDIKWSHUJS 
| 


EDGWFDJHJHVBTFDEFI JHUHGVYGEDIKJWMAI JMESGBNGFDYHJWYDHSJDGHDSH 


| ESYHIJRFDYHRF DSUHNGFDUHJNMHGFCOLGFPLYHGPLYGKKJSDBNMXHHGJHSSH 


DJHEVEUY BCABKJHSDGAYUI BHIVCGARYUBVNMCBHJKHGSHI UGWSAPHJSTRGSS 


| 
| 
{ 
WIQSPOUABNXZDFBKDWSAISFDJHKEWRYUFDKSGAHJDASSSDHISDAFNBAHISDH | 


Figure 12 


The letters of an unknown encripted message are written onto long 
strips in order to use the Kappa Test to discover repeated characters. 


This is strictly a statistical method, and its main use is to spot 
when a cipher alphabet repeats. This technique was devised by 
William Friedman, the American cryptanalyst who cracked the 
Japanese “PURPLE” cipher. Friedman realized that there arc 
certain mathematical principles governing any effort at 
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cryptanalysis. One of them is what he called the “Index of 
Coincidence.” This means that the chances of getting pairs in 
chains of letters written randomly are .0385. To give a practical 
example, let’s say that we have two lines of letters, one above 
the other, and that both are totally random. The chances of 
having two identical letters above each other are .0385.!4 


Now let’s take the case of English text, in which letter 
frequency is not at random. In 1000 letters of English text, we'll 
find 130 “E”s and 80 “A”s, etc. The chances of finding identical 
letters with two superimposed texts is 0.0667. This means 6.67 
for each 100 pairs of letters. This figure varies for each language, 


just as frequency count of letters does. 


The practical value of the Kappa test is to discover the 
“period,” or key length, of an unknown polyalphabetic cipher. 
I's helpful to write the letters of the unknown encryption out 
on strips, and to slide them over each other (see Figure 12 on 
page 88). This is simply a mechanical convenience to avoid hav- 
ing to write the text again for each trial. 


Let’s take a couple of strips to see how the Kappa test works: 
UGQMG F CAXWBWGWFMWN J ZYUNERRQLDZ AS L|UNVXDVDWTBKDFCKCBQKDOBHGGV 1 


SDFGHJKLWERDFCVBYUHJJKNMCGYNJJ WEEDCRFVYHJUJKUIKOLOLPLPTYHJNM 
x x 


We see that, out of 60 letter pairs, we have two cases of 
doubled letters, which works out to .033%. This fits the notion 
of simple coincidence. Now we take the two strips and slide the 
lower strip one space over: 


(}GQMG FCAXWBWGWFMWN J ZYUNERRQLDZAS ITUNVXDVDWT BKDFCKCBQKDOBHGGVI 


SDFGHJKLWERDFCVBYUHS ‘KNMCGYNJ JWEEDCRFVYHJUJKUIKOLOLPLPTYHJNM 


x x x x 


We now find four pairs, or .066%. This suggests that the 
cipher alphabets are synchronized, and that we can proceed with 
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multiple solutions by working down the columns of the 
ciphertext. 

There’s a catch. There always is. Much depends upon samplc 
size. A short text is less likely to conform to the pattern than a 
longer one. Therefore, the figures you get when you try this may 
not be exactly right. In rare cases, you might obtain figures that 
show exactly the opposite. You have to work the odds, though, 
and go with the best chances, while remaining mentally prepared 
for the exceptional case. 

There’s yet another statistical test, known as the “phi,” fo 
finding whether a column in a stack is truly enciphered with the 
same alphabet. Let’s say that we’ve got a stack fifty letters deep. 
We start by multiplying that number by the same number minus 
1. This reads out to: 

50 x 49 = 2450 


We take this and multiply it by our Kappa figure for 
polyalphabets, which is .0385, giving us 94.325. We then take 
the same figure and multiply it by our monoalphabetic Kappa, 
which is .0667, giving us 163.415. We then do a frequency 
count in the column or message. We take the total for each lette: 
listed and multiply it by that number, minus 1. If we have 3 
“A”s, for example, we don’t square 3, we multiply it by 2, giving 
6. We go through this for all of the letters listed. Let’s say they 
are: 

A C E F J M O R T W Z 

3 4 1 6 7 5 8 4 5 3 3= 49 

6+ 12+ 1+ 30+ 42+ 20+ 56+ 12+ 20+ 6+ 6= 211 


That’s quite a bit over the 163.415 figure for a monoalpha 


betic cipher, which makes it almost a sure thing that this one 
is correctly stacked. Let’s see how this procedure would shape 


up if there had not been as many high numbers in our count: 
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ACDEFHJLMOQRS TVWX Z 
3 213 323 323 4 3 3 «13 3 4 *4= 50 
6+ 2+ OF 6+ 6+ 2+ 6+ 6+ 2+ 6+ 12+ 6+ 6+ OF 6+ 6+ 12+12=102 


102 is very close to our polyalphabetic figure, 94.325. If we 
get a result like this, we can safely assume that we don’t have 
it stacked correctly, and we ought to try shifting one or more 
rows and do another test. 


The chi test compares two messages, and can determine if 
they’ve been enciphered with the same key. You do this by 
counting the numbers of letters in each message, and multiplying 
them together. If you feel that the messages are monoalphabetic, 
you multiply the product by the monoalphabetic Kappa figure, 
which is .0667. This gives you the calculated chi for mono- 
alphabetic substitutions. You then multiply the same product by 
the lower figure, .0385, to give you a calculated chi for 
polyalphabetics. 

The next step is to multiply the number of “A”s in one 
message by the number in the other. You do this for every letter, 
and add the results together. How do they compare with the two 
figures you’ve already worked out? 


THE PLAYFAIR CIPHER: 
SPECIAL TECHNIQUES 


As we saw from a previous chapter, the Playfair suppresses 
frequency count somewhat, and provides variable substitution 
according to each letter’s neighbor in the pair. The Playfair is 
somewhat more tedious to dissect than a simple substitution, but 
it’s vulnerable to analysis because it leaves its “fingerprint” on 
messages. 
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Several suggestive features help identify a Playfair. These 
aren’t totally conclusive, but they point very strongly. One is that 
the frequency count is based on 25 letters, with usually the “I” 
or “J” missing. Another revealing feature is that a Kasiski 
superimposition shows only two alphabets in use. We also neve: 
find pairs consisting of doubled letters. Finally, the messages 
always have an even number of letters. 


We have to change our thinking somewhat when working 
with a Playfair. We know that we’re working with a two-lette: 
“alphabet” of about 600 pairs. Likewise, the pattern of 
substitution is limited. In unraveling a Playfair, it’s good to keep 
in mind that the system has certain weaknesses. A certain word 
has a 50-50 chance of having the same ciphertext, whatever its 
position in the message, whereas with a polyalphabetic 
substitution, it would be very rare that the same word would 
encipher exactly the same twice. This is one of the distinguishing 
characteristics that allow the code-breaker to tell that he’s 
working with a Playfair. The only reason a certain word would 
generate a different ciphertext is that it might break into different 
pairs, according to its position in the message. For example, 
NEED could divide as “NE ED” or with the first and last letters 
as parts of other pairs: “-N EE D-.” In any event, a word can 
encipher only two ways with a Playfair. 


Another characteristic is that a pair substitution done on the 
diagonal will always be reciprocal. If “OG” stands for “TH,” 
then “TH” also stands for “OG.” Even a simple substitution 
cipher doesn’t have this weakness. However, this doesn’t work 
for letter pairs on the same line, vertical or horizontal. 


Another characteristic is that, despite the theoretical possibil- 
ity of over 600 pairs, each letter can have only those adjacent 
or diagonal as substitutes. Also important is that only letters in 
the same column or row as the high-frequency letters, ETAON- 
RISH, will have high frequencies in the enciphered message. 
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LETTER PATTERNS 


In English, as in any language, there are not only certain 
letters that occur more often than others, but certain combina- 
tions that predominate. For example, the combination “TH” 
occurs more often than any other. “HE” is the next most 
common, with “AN” and “IN” following. Likewise, three-letter 
combinations, or “trigraphs,” also have their frequencies. “THE” 
is the most common, with “AND” and “THA” not far behind. 
There are also “contact frequencies,” tables of probability of 
letters’ being adjacent. For example, the letter “A” has “N” on 
its right side 21% of the time, and “H” on the left 14% of the 
time.!5 


The value of these contact tables comes after the initial break 
in the cipher. Statistical analysis can provide the locations of a 
few common letters, but the cryptanalyst must use common 
sense, intuition, and probability tables to dope out what letters 
precede or follow them. For example, the letter “E” may have 
emerged in this combination: 


Ciphertext: UGQMGFCAXWBWGWFMWN 
Cleartext: ee e | e 
We know that this is our test message; “I need you. Come 
at once,” but the code-breaker doesn’t. He has a double E, and 
this is his first line of attack. There are only a few words using 
a double E, such as “MEET,” “MEETING,” and “NEED.” The 
T also offers a clue, because the most likely letter on its left is 
“A,” and the most likely letter to the right is “H.” We know that 
“A” is correct, but the code-breaker will have to do it by trial 
and error. Cribbing from the message’s context sometimes helps. 
In the above ciphertext, words are not run together and 
chopped into groups of five. Let’s see how much easier his task 
would be if the words were normally separated: 
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Ciphertext. U GQMG FCA XWBW GW FMWN 
Cleartext: ee e t e 


This is a good example of how even a simple messayc 
becomes very obscure when word length is eliminated. Word 
length and breaks are other aspects that the code-breaker has to 
reconstruct. 


BREAKING TRANSPOSITION CIPHERS 


Simple transpositions yield to trial and error. Paper slides o! 
ten help provide a break into the pattern. The code-breaker has 
to consider every possibility, such as the letter order running up, 
down, diagonally, in a spiral, etc. 


One technical aid is the paper slide. Writing the message 
vertically on strips of paper and pairing them in various orders 
gives test pairs. Checking these for likely digraphs helps find 
which columns belong next to each other. 


With a transposition cipher, the code-breaker can gain a lot 
of help from cribs. Knowing the context of the message help: 
dope out some probable words. Anagramming locates the letters 
that make up probable words in the columns and rows of the 
ciphertext, and arranging the other letters to suit the pattern will 
bring out the rest of the message. 


Having several messages enciphered with the same transpo 
sition cipher provides a tremendous advantage if there are rc 
peated sequences between two or more messages. These cai 
help force an entry into the cipher because they suggest that the 
same phrase or sentence is common to both messages. This 
characteristic cuts down the number of trial and error grids be 
cause it eliminates all in which the letters don’t fit in the samc 
relationship to each other. 
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Grills are somewhat harder to break, and the code-breaker 
depends a lot upon intuition, as in solving anagrams. 


COMPUTERS FOR CRYPTANALYSIS 


The first computers of the modern era were employed for 
cryptanalysis. During WWII, the British code-breaking 
establishment built several rudimentary computers to help them 
obtain the keys of the German “Enigma” cipher system. After 
the war, the British and American governments sponsored the 
development of new models of computers for code-breaking. 
Almost all of this is classified, and we don’t know how many 
computers are at the National Security Agency. 


THE NATIONAL SECURITY AGENCY 


This super-secret agency has probably the world’s best 
resources for code-cracking. It’s generally known that the NSA 
has had computers for both code-making and code-breaking 
since its beginning in the late 1940s. If a cryptanalyst has a 
properly programmed “mainframe” computer, he can do at least 
the following tasks very quickly and easily: 


Compile a list of the most common letters in a particular 
language and their frequency. 

Compile similar lists for digraphs and trigraphs. 

Compile a list of most commonly-used words in that 
language. 

Compile similar lists for special traffic, such as a target 
country’s military communications. 


Analyze a message or group of messages for frequency count 
and other characteristics. 
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Run a phi and a chi on a message in every likely combination 

Run test decipherments at a speed far faster than any human 
operator. 

Cross-match code groups against others, singly and in 
combination, to find matching clusters. 

The exact capabilities of the computers at NSA and the uses 
they see are classified. However, knowing that modern 
“supercomputers” have phenomenal calculating speeds and 
memories, we can speculate. Supercomputers are already into 
their second generation at this writing, and a third will be along 
any day, with enhanced capabilities. The following tasks, if not 
quite possible with today’s machines, soon will be: 

Storing the texts, including page numbers, of every dictionary 
printed. This would allow running comparisons with intercepted 
code groups to determine if they correspond to coherent texts 
using these dictionaries. 

Storing every message ever intercepted, and periodically 
making electronic comparisons to determine if they’re in similai 
crypto-systems. 

Making statistical comparisons of messages received in clea 


to determine if any correspond to encrypted texts in the 
computer’s memory. 


Another possibility is that a supercomputer can analyze 
ciphertext by running contact pairs, and make a start at restorin z 
the plaintext, without a human operator’s intervention. This is 
strictly a statistical method, and can be automated. 


THE HOME COMPUTER 


What about the code-breaker who has only a home compu 
ter? He can also do a few things, without fancy programming, 
to break codes and ciphers. One technique is to keyboard the 


batch of messages and stack them. Let’s see what that can look 
like: 


UGQMGF CAXZBWGWFMWN J ZYUNERRQLDZASITUNVXDVDWTBKDFCKCBQKDOBHGGVI 


SDFGHJKLWERDFCVBYUHJ JKNMCGYNJJWEEDCRFVYHJUJKUIKOLOLPLPTYHJNM 


LKJHGFFDPOI JHGFBVXSREWREQRFDCWEDFVYFDZRTYJMUHGVCTYUJ IUYTREWQ 
QSXEDFVRFAZASZXEDEDRDFCRFEDUJKWSUJRDFCOLYHGFCPKJYIYGGOJFJFUF 


YHJTFYHNTFDGBNVCXVBNMBVCXZVBDS GHJKREYUJKRFDYHEDIKEDIDJDUJIOW 


WQQWESADFGSUJDSYHJFTYCBNSYHJSLWPISOKDOKDIUJSYHNESUJDILWSHUJS 


EDGWFDJHJHVBTFDEFI JHUHGVYGEDIK JMWAI JMESGBNGFDYHKWYDHS JDGHDSH 
ESYHIJRFDYHRFDSUHNGFDUHJNMHGFCOLGFPLYHGPLYGKKJSDBNMXHHGJHSSH 


DJHEUEUYBCABKJHSDGAYUIBHJVCGARYUBVNMCBHJKHGSHIUGWSAPHJSTRGSS 
WIGS POUABNXZDFBKDWSAISFDJHKEWR YUFDKSGAHJDASSSDHJSDAFNBAHJSDH 
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With a computer, it’s possible to run through some manipu- 
lations that would take hours with pencil and paper. One 
example is sliding the message strips around in different orders 
to check for transpositions, as shown in Figure 13. 


Figure 13 


Using a computer, you can search for transpositions in a matter of 
seconds using only a few keystrokes. The highlighted trial shown above 
took only about 30 seconds. 


Computer manipulation is also useful for stacking polyalpha- 
betic ciphers to check for periodicity. A lot of this is trial and 
error, with a lot of time spent writing letters on paper. With a 
computer, it’s only necessary to keyboard the texts once. 
Manipulation is then possible with only a few extra keystrokes. 
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There are cryptanalytical programs in BASIC for the home 
computer buff. These check a message for digraphs, trigraphs, 
index of coincidence, matching alphabets, and other character- 
istics. Although they’re not a substitute for a gifted human 
cryptanalyst, these programs save many hours of donkey work.!® 


CONCLUSIONS 


Code-breaking is both a science and an art. It depends upon 
both for cracking basic crypto-systems, but the code-breaker 
needs much more to crack high-security systems. Luck played 
a crucial part in many important cases. So did the availability 
of cipher machines on the open market, and the willingness to 
steal codes and ciphers when necessary. The amateur code- 
breaker’s resources are limited, and a realistic appraisal suggests 
that he’ll be better off finding his information by other means, 
if available. 
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Quasi-Cryptosystems 


There are several types of crypto-systems which aren’t, strictly 
speaking, for secret transmission of information. Although not 
originally designed for coding, they offer some communication 
security as a by-product. 


SQUIRT RADIO 


“Squirt radio” sends a message at many times normal speed, 
sharply reducing transmission time and vulnerability to 
direction-finding. This technique originated with the German 
espionage services during WWII, and enabled their agents to 
send radio messages back to base with much reduced risk of be- 
_ing pin-pointed by triangulation. 

Although the agent’s messages were coded, squirt transmis- 
sion wasn’t to enhance message security. It helped protect the 
agent because radio-location techniques of the era required 
many minutes to carry out. When a direction-finding network 
detected an unknown or suspect transmission, it was necessary 
to alert at least two, preferably three, direction-finding stations 
to get a “fix” on it. For best results, these stations had to be many 
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miles apart to give a good baseline for triangulation, and co- 
ordinating them required telephoning back and forth.! 


The old trick of transmitting on a frequency adjacent to an 
established transmitter no longer worked well because of the in- 
creased sophistication of detection devices. A central control 
station might have hundreds of cathode-ray tubes showing every 
transmitter in the spectrum, and any new ones would be im- 
mediately apparent, however close they were to the station 
supposedly shielding them. 


The hardware for squirt transmission consists of a two-speed 
tape recorder and a radio transmitter. The operator turns his re- 
corder on to slow speed, plugs it into his transmitter, and taps 
out his enciphered message, using his radio’s morse key. He then 
rewinds his tape, turns the transmitter on, and raises home base. 
This takes only a few seconds if all goes well. He then runs the 
tape through at high speed. Depending on the length of the 
message, transmission takes only a few seconds, not enough for 
any “goniometric” receiver to get a fix on it. The operator at 
home base has a tape recorder set up to record the message at 
high speed. Playing it back at slow speed allows listening to the 
message. 


The squirt transmitter isn’t as effective today because of in- 
creasingly sophisticated and automated direction-finding 
equipment. Today’s military have electronically interlocked 
direction-finding stations, where goniometric receivers scan the 
frequencies for unknown or suspect signals. When a receiver 
picks one up, it transmits a signal to the central computer, which 
commands other receivers at remote sites to search and record 
on that frequency. Direction-finding is almost instantaneous. 
Accuracy is enhanced because comparing azimuths is no longer 
the only way to locate the source of a signal. The computer 
compares relative signal strength from several receivers. Using 
an extremely precise clock, it can also compare the times the 
signal arrives at each receiver. Synthesizing the three techniques 
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gives a very close approximation of the unknown transmitter’s 
location, and much more quickly (only a couple of seconds) 
than was possible during WWIL. 


THE TRUNKING SYSTEM 


Police agencies are getting squeezed in communication 
channels. Although the number and size of police agencies in this 
country is increasing, and so are the workloads, there is a finite 
number of radio channels available for police use. One way of 
handling the problem is “trunking” radio channels. 


“Trunking” means that many channels are computer- 
squeezed onto a few radio frequencies. The central computer 
takes advantage of the “dead time” on each frequency. 
Normally, a frequency used for voice traffic doesn’t have a voice 
on it every instant. There are periods of silence, but only a com- 
puter can monitor all of the available frequencies and pick up 
the dead time. When a police operator keys the microphone, the 
computer will scan all available frequencies, and when one is 
free, will transmit the conversation on it, switching it back and 
forth between frequencies as necessary, and inserting portions of 
other conversations when dead time develops on each channel. 


An eavesdropper can listen in with a police monitor, a 
receiver tuned to the police frequencies, and hear a coherent 
conversation on any frequency. However, if more than one 
conversation begins, the computer will start shuffling them from 
frequency to frequency and the eavesdropper will have a hard 
time following a particular conversation. Although the trunking 
system is in no way a “scrambler,” it serves the same purpose 
in frustrating the unsophisticated eavesdropper. 


as cae 
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MULTIPLEXING 


This commonly-used technique transmits several channels of 
communication on the same frequency. Multiplexing is an 
electronic mixing technique that sees commercial use in FM- 
stereo broadcasts, for example. Although multiplexing is only for 
squeezing more information into a limited band, it’s more secure 
than ordinary FM because it requires a special receiver to listen 
in. 


LIGHT PIPES 


Photo-optic “light pipe” communication is practical, using 
glass-fiber optics and special amplifiers and receivers. This offers 
some security from eavesdroppers. 


Electronic telephone communication travels along wires, 
which are easy to tap, or on microwave channels, also easy to 
intercept. It’s not necessary to cut and splice a telephone wire 
to monitor the traffic. A magnetic induction coil will do the job 
without leaving a physical trace. Long-distance telephone 
communication using microwaves is not secure because a 
discreetly disguised antenna and receiver anywhere along the 
route will pick up the messages. 


Light pipes are not total protection against eavesdropping, but 
they don’t radiate energy that can be picked up with induction 
coils or antennas. A long-distance system using light pipes is 
somewhat more secure against interception. 


AUTHENTICATION CODES 


The only message an “authentication code” transmits is that 
the bearer or source is genuine. A bank official issuing a large- 
figure certificate of deposit will ask the client for his mother’s 
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maiden name as an identifier. This is extra protection in case an 
impostor tries to withdraw the funds. 


Military units use authentication codes to verify that orders 
are genuine. In certain critical installations, such as those 
equipped with nuclear weapons, these codes are different every 
day. The President of the United States has a 24-hour assign- 
ment of warrant officers who carry the “football,” a satchel 
containing the authentication codes for nuclear attacks. These 
“bagmen” travel with the President wherever he goes. At the 
receiving end, officers in charge of launching nuclear weapons 
carry cards with the authentication codes. Upon receipt of a 
message, at least two officers must compare their codes and 
agree that the message is genuine before they can act upon it.? 


SOURCES 


1. Clandestine Operations, Pierre Lorain, NY, MacMillan 
Publishing Company, 1983, pp. 28-42. 


2. The Code-Breakers, David Kahn, NY, MacMillan, 1967, p. 
717. 
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Communication Security 


When it becomes necessary to transmit secrets, it’s vital not 
to compromise them by errors and carelessness. That’s what this 
chapter’s all about. It’s as much a list of “do’s” as it is a list of 
“don’ts.” Communication security is extraordinarily difficult 
because it’s not enough to be strong and prepared in a few ways. 
It’s vital to be defensive at every point and in every direction. 


One extraordinarily annoying fact about crypto-systems and 
their messages is that someone can steal them without leaving 
a trace, and without your becoming aware that they’re no longer 
secure. This is because secrecy is intangible. Stealing a tangible 
object leaves its owner aware that it’s gone, but tapping into a 
telephone line does not stop messages from getting through. 
Likewise, intercepting a radio transmission doesn’t stop it or 
even alert the sender that someone else is listening. 


At the outset, deciding on a security policy sets the stage for 
everything else. It’s important to understand the nature of 
secrecy, and how telling more people a secret increases the risk 
of exposure. This means that any crypto-system should not be 
spread indiscriminately but only on a “need-to-know” basis. The 
same applies to physical assets, such as code and cipher books, 
pads, and papers. 
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SAFEGUARDING CRYPTO MATERIALS 


Governments keep their cryptographic materials behind bars. 
Code books and cipher machines are always in locked rooms, 
with only specially cleared persons allowed inside. In many 
cases, code rooms are electronically screened to prevent eaves- 
dropping. Current comes in through specially shielded cables, 
and transmissions are also specially protected. This is because, 
as we've seen, it’s possible to obtain the key settings of cipher 
machines by tapping into telephone or electric power wires. 


The more modest user of crypto materials, who doesn’t have 
the resources of a government to back him, needs simpler 
methods. The basic technique for the small user is to keep a “low 
profile.” While it would be ridiculous to deny that an embassy 
has crypto facilities, a typical home or office usually doesn’t. The 
best policy is simply to keep it quiet. 


If it's necessary to cross frontiers or otherwise run the risk of 
1 search, any crypto material must appear totally unconnected 
with this purpose. Items such as one-time pads and secret inks 
are poor choices because, if found, they’re give-aways. A dic- 
lionary or other book used for coding is a good choice because 
it has an innocent purpose, and books of all sorts are very com- 
mon. 


If you’re a businessman using cryptography, designate a 
special room or office for the task. Don’t call it the “code room.” 
Instead, call it the “special auditing office” or another un- 
interesting name. The room should be at the interior of the 
building, without windows or extra doors. Keep the door 
‘ocked, and make one person responsible for the security of the 
‘oom and materials it contains. There should always be a second 
ayer of security, such as a locked desk or filing cabinet for 
itoring both crypto material and messages. 
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Although it may seem convenient to have a copier inside the 
code room, don’t. This makes it too easy to copy restricted 
material. While it’s possible to place a lock on the machine, and 
have a rule that no copies are to be made without two employees 
present, this isn’t easy to enforce. Yes, there are machines with 
counters, and there are ways of keeping logs of copies made and 
checking them against the machine’s counter, but these systems 
aren’t secure. They’re too easy to bypass by falsification and only 
a massive audit would reveal the deception. The best, and 
simplest way is to keep all copiers outside the room. There, you 
can be sure that anything that goes on the copier will already 
have been paraphrased. 


Another point is to dispose of carbon copies and worksheets 
securely. Much important information has come into the hands 
of unauthorized persons who poke through trash. A paper shred- 
der costs several hundred dollars. A cheaper way is to drop the 
paper into an incinerator or dispose of it in a fireplace, always 
stirring the ashes afterwards. 


SECURITY OF PERSONNEL 


If you’re going to use secret communications, it’s good policy 
to restrict knowledge to trustworthy people. The military arm 
their code clerks, but this isn’t always practical or even necessary 
in civilian life. It’s very unlikely that armed paratroopers will be 
dropping down onto your lawn to kidnap you or to steal your 
codes. 


Although there’s no danger of armed attack, carelessness, 
stupidity, and greed can cause as much damage. If you’re run- 
ning a business in which confidentiality is important, you need 
people who show loyalty, and who have the maturity to handle 
the responsibility. If you’re in a highly competitive business, in 
which industrial espionage is common, don’t rely on “employee 
screening” methods to weed out incompetent or dishonest ap- 
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plicants. Anyone whom you assign to operate crypto-systems 
should have a proven track record with your company. They 
should also have demonstrated good judgment and a sense of 
proportion. It won’t do to bring friends in to see where they 
work, for example. They should also understand that talking too 
much about their jobs can compromise security. 


COMPARTMENTALIZATION 


The big risk in cryptography is that anyone who breaks your 
code or cipher may have access to all of your secrets. One way 
to avoid this is a system of strict compartmentalization. If you 
have several offices with which you must keep in touch, use a 
different crypto-system for each. This prevents anyone from 
unlocking the entire operation by cracking or purloining one 
code or cipher. 


IMPORTANT DON’TS 


We've seen how using a length of ciphertext allows the code- 
breaker to line up segments with paper strips or with a computer 
to make a mathematical analysis and pry open the system. It’s 
evident that if the code-breaker has cleartext to go with the in- 
tercepted message, it will speed up his work and make it much 
easier. This is why these “don’ts” are so important: 


Don’t send a message in one code or cipher, then repeat it in 
clear. As we’ve seen, doing this provides a code-breaker a good 
crib to use against your crypto-system. \ 


There’s another important side to this type of security. Don’t 
publish or release to a third party any material that’s been 
transmitted to you in crypto without paraphrasing it. If you 
paraphrase it, you impede efforts at comparisons of texts, and 
avoid unwittingly giving away your crypto-system. If you’re a 
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businessman, you might establish a rule that anything leaving the 
code room must be paraphrased. 


Don’t transmit any text or documents given to you without 
paraphrasing them. Any such document could be a set-up, to 
enable a code-cracker to have the same text in clear and in your 
system for comparison. The exceptions are documents given you 
by trusted people in your organization. 


Don’t send part of a message in cipher and part in clear. This 
should be obvious, but many still do it. Sending a message such 
as “DFGH NHYU BFI DC TERRYVILLE.” suggests to even 
a mediocre code-cracker that the message reads “WILL MEET 
YOU AT TERRYVILLE.” Anyone with knowledge of your 
movements can confirm the meeting. 


Don’t send the same message in two different systems. This 
again allows comparisons which can unravel both systems. If 
you have to send the same message to parties using two different 
crypto-systems, paraphrase one message, or send it by courier. 


Don’t risk compromising your crypto-system for the sake of 
one message. If there’s any problem with your crypto-system, 
correct it before transmitting any messages. Under no circum- 
stances should you transmit in part crypto, part clear. It’s better 
to sacrifice the secrecy of that message by transmitting only in 
clear, and safeguarding your crypto-system. 


Don’t use stereotyped expressions or boilerplate language. 
Using boilerplate results in sending the same message, or part of 
a message, to two different parties. We’ve already covered the 
disadvantage that brings. 


Don’t fail to change keys at proper intervals. What are proper 
intervals? There’s no exact answer. If you have a large volume 
of traffic, you may wish to change keys each day. If volume is 
low, once a month should be enough. Much depends on the skill 
of any code-breakers you think you’re facing, and how long it 
takes before the messages become obsolete. If the information 
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you transmit loses value very rapidly, you may feel that no code- 
breaker can crack your system quickly enough for the inform- 
ation to be useful. 


You're probably correct, but what about the next series of 
messages? Cryptanalysis brings many benefits down the road, 
and insights gained today will help break encrypted messages 
tomorrow. 


Another point is to change at least the keys whenever a 
trusted employee with access to the crypto material or the 
messages leaves your employ. This is particularly true if the em- 
ployee goes to work for the competition. You'll always have the 
nagging suspicion that confidential information was his ticket to 
the new job. 

Don’t fail to report the loss or compromise of a key, code, 
or cipher immediately, and to stop using that system. 


Don’t fail to keep at least one set of back-up keys, ciphers, 
or code on hand at all times, ready for use. The system in use 
may be compromised at any moment, and it’s wise to have 
another ready to go. 


TELEPHONE SECURITY 


Security of telephone conversations, never good, has been 
declining during the past couple of decades. With many long- 
distance telephone conversations transmitted by microwave, 
they’re accessible to anyone with the right equipment. Cellular 
phones are becoming popular, and these put even local calls on 
the air. So do portable phones available in electronic stores for 
under one hundred dollars. All of these are vulnerable to inter- 
ception by our own and even foreign governments. Satellites 
pick up conversations and relay them to their governments’ elec- 
tronic snooping offices on Earth. Computers scan the speech, 
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seeking certain key words which suggest that the conversations 
may be worth the attention of a human operator. 


Private snoopers, such as business rivals, have more modest 
resources. They’re limited to tapping a line, and one fairly good 
way of foiling this is to use a public phone for each end of the 
conversation. Each party keeps a list of numbers of public 
telephones that are conveniently near. Each one is numbered. To 
avoid disclosing that a private conversation’s about to take place, 
there should be no mention of using a public phone. Instead one 
party telephones the other and says something like: “How about 
meeting me for a drink at five?” or, “I can’t make our meeting 
because I have to pick up my car at five.” or, “We'll be able 
to meet because I’m going to make sure to leave the office right 
at five.” 


“Five” is the critical word. This signifies the number of the 
telephone which the calling party will dial at a pre-arranged in- 
terval after he hangs up. If this is unsatisfactory, the other person 
replies with another number, again working it into a sentence 
to make it appear to be an innocuous conversation: “I can’t 
make it then. How about six?” or, “I thought you said your car 
wouldn’t be ready till six.” or, “That’s good. I usually leave 
around six, but I'll cut it short tonight.” 


This tells the caller to dial listing number 6 at the proper time, 
instead of phone number 5. 


SCRAMBLERS 


We’ve already covered these in a previous chapter, but here 
we have to consider the practical aspects. First, scramblers are 
expensive. You can expect to pay several hundred dollars for the 
cheapest set. A scrambler is useless unless the other party has 
one, too. This means that their usefulness is very limited, as you 
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can’t just dial anyone you know and have your conversation It’s far better to have entire sentences or meanings together: 
scrambled. 

Scramblers also vary in reliability. Keep in mind that both the PETS cc Fal vig hn Ga ieeha RET E Ce SERA I am going to meet 
transmitting scrambler and the receiver have to be synchronized FF el 9, re a ne I need to meet 
to pass speech properly, and that often the synchronization slips. ADMIRE ............cccccceccceceee We must go to 
This is a surprisingly persistent problem, especially with the BAKER |... occ ccocccceecc cee eee. John Smith 
aheaper det. BASKET .0.........000eceeeeeee eee. Robert Smith 

DUE ie iwcvncewadssiascianvesswian John Jones 
DISCRETION OE wacies abensnrnmers ewacenucamnenimnems At home 
LGIVG ou che te wtareieksdsshiereniniaet At the airport 

The simplest defense against electronic snooping is discretion. CROW... 2. eee nes At the office 
Don’t say anything on the phone that you don’t want splashed Per racer druvivansskseerecenssias 36 This is urgent 
over the front page of your local newspaper the next day. This DEIR, ccna nincenowsegtiawenie This is not urgent 
is an overly dramatic way of phrasing it, but it stresses the SOONG sinwtsrasxaieagwimnie vex Come here at once 
importance of avoiding discussion of sensitive information. ATER TG: 5. ue weds Kwak ouravadiaumaetinicasele Noon 

HACE. cihnceulareusceesn emcees One o’clock 
TARA, Gocretinnentmres iievereoxerwe eleva Two o'clock 
siecle VOM cig rekare eieieniaimalevkere: Three o’clock 

A “pocket code” is a short list of code words or a cipher grid a te at cc. perp hh ap ae 
that will fit into a wallet. Ideally, it shouldn’t be bigger thana tris nese ee sesseeeeen ene 

” ED . . | Pd.) Rr ee terrane PET Teer er ee Six o’clock 
3” x 5” card, which can fold over once for compact carrying. S ‘clock 
However, a standard sheet of paper will also do if there are MAN 1.0.0... eects ohana ene ne 
many code phrases to communicate, but it will be slightly more NO) Eight o'clock 
awkward. INICE® 5 Sos, Sak tse ss Serer as aeteeeaares Nine o’clock 

In constructing a pocket code, there must be the same close BEERS usantacasabensnesiaencetantess Tes see 
attention to good practice as when compiling a major code on a Eleven ore 
cipher. It’s a serious mistake to use only fragments of code in- a Se Twelve o'clock 
serted into sentences. For example, the sentence “I’m going to PRETTY ... 2.0.20. se eee e eee e teeters A.M 
meet Challenger at Grand Central Station at five o’clock” tells PUTTY 0.5 0.cistarsanexsentavesrcieress evans P.M. 
the listener that a meeting is about to take place, where it will SAE wns naccee ave eddy eens As soon as possible 
be, and at what time. The only question is “Challenger’s” SOUT sswsdrnuceiwereseernraetes Will wait for reply 
identity. RS ho ec ir inixsom dee octamer e's ai nes Have... contact me 
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The list on page 117 covers enough possibilities to show how 
a pocket code can work to hide the meaning from an eaves- 
dropper. A longer code can cover more ground, but will be 
harder to use quickly. 


The pocket code requires the same sort of security that applies 
to other codes. It belongs in the wallet and on the person at all 
times. Leaving it in a desk, glove compartment, or hotel room 
provides opportunities for its loss or compromise. 


RADIO 


It’s occasionally necessary to use some form of two-way radio 
in business and in our personal affairs. While it’s unlikely that 
someone we want to avoid will be listening at exactly the 
moment we transmit, we should still observe discretion. Using 
a Citizens’ Band channel or the Commercial Band doesn’t make 
much difference regarding security. The only difference is that 
there’s much less chance of interference from private citizens 
“talking trash” on the Commercial Band. 


Using guarded speech and perhaps a pocket code will enhance 
security on the air, but it’s important to avoid transmitting any 
information that doesn’t absolutely have to go at that moment. 
If it can wait for a face-to-face meeting, it’s better to avoid saying 
it. 


If the matter’s very urgent, it may be possible to use a landline, 
or public telephone. Granted, these aren’t very secure, but using 
a phone for a brief message is usually better than putting 
sensitive information on the air. Using pre-arranged public 
phones offers the best hope. An office or home telephone might 
be tapped. 
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YOU WILL ALSO WANT TO READ: 


O 10046 THE CODE BOOK: All About Unbreakable 
Codes and How to Use Them, by Michael E. Marotta. 
No prior knowledge of mathematics is necessary to understand 
the easy-to-follow directions in The Code Book. One-time pads, 
modulo based codes, public key systems, function ciphers, and 
much more are covered in detail in this amazing book. Obscure 
secrets known only to international espionage agents and pro- 
fessional cryptographers — now revealed for YOU to use! 1987, 
5% x 8%, revised, 106 pp, illustrated, soft cover. $9.95. 


O 55046 LIP READING MADE EASY, by Edward B. 
Nitchie. Here's a James Bond-type skill every operator should 
be familiar with — “listen” in on conversations you can’t hear! 
Find out what deals are being made over seemingly casual 
lunches. Eavesdrop to your heart’s content. Learn secrets — 
secretly! The author taught thousands of people to read lips. His 
easy-to-use illustrated method enables you to become a creative 
spy in just a few short lessons. 5% x 8%, 136 pp, illustrated, soft 
cover. $7.95. 


O 61082 HOW TO DISAPPEAR COMPLETELY AND 
NEVER BE FOUND, by Doug Richmond. Heavy-duty dis- 
appearing techniques for those with a “need to know!” This 
amazing book tells how to arrange for new identification, plan 
for a disappearance, avoid leaving a paper trail, case histories, 
and more. The author shows you how to pull off a disappear- 
ance, and how to stay free and never be found. 1986, 5% x 8%, 
107 pp, soft cover. $12.95. 


And much more! We offer the very finest in controversial and unusual 
books — please turn to our catalog announcement on the next page. 
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Port Townsend, WA 98368 
Please send me the titles I have checked above. I have 
enclosed $ (including $3.00 for shipping and 
handling). 
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Address 
City 
State/Zip 


Washington residents please add 7.8% sales tax. 
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“Yes, there are books about the skills of apocalypse — spying, surveillance, fraud, 
wiretapping, smuggling, self-defense, lockpicking, gunmanship, eavesdropping, car 
chasing, civil warfare, surviving jail, and dropping out of sight. Apparently writing 
books is the way mercenaries bring in spare cash between wars. The books are 
useful, and it’s good the information is freely available (and they definitely inspire 
interesting dreams), but their advice should be taken with a salt shaker or two and 
all your wits. A few of these volumes are truly scary. Loompanics is the best of the 
Libertarian suppliers who carry them. Though full of ‘you’ll-wish-you’d-read-these- 
when-it’s-too-late’ rhetoric, their catalog is genuinely informative.” 

—THE NEXT WHOLE EARTH CATALOG 


THE BEST BOOK CATALOG IN THE WORLD!!! 


We offer hard-to-find books on the world’s most unusual 
subjects. Here are a few of the topics covered IN DEPTH in our 
exciting new catalog: 

® Hiding/concealment of physical objects! A complete 
section of the best books ever written on hiding things! 

® Fake ID/Alternate Identities! The most comprehensive 
selection of books on this little-known subject ever offered 
for sale! You have to see it to believe it! 

@ Investigative/Undercover methods and techniques! 
Professional secrets known only to a few, now revealed to 
you to use! Actual police manuals on shadowing and 
surveillance! 

@ And much, much more, including Locks and Lock- 
smithing, Self-Defense, Intelligence Increase, Life Exten- 
sion, Money-Making Opportunities, and more! 

Our book catalog is 82 x 11, packed with over 500 of 
the most controversial and unusual books ever printed! 
You can order every book listed! Periodic supplements 
to keep you posted on the LATEST titles available!!! Our 
catalog is free with the order of any book on the 
previous page — or is $3.00 if ordered by itself. 


Our book catalog is truly THE BEST BOOK CATALOG IN THE 
WORLD! Order yours today — you will be very pleased, we 
know. 


LOOMPANICS UNLIMITED 
PO BOX 1197 
PORT TOWNSEND, WA 98368 
USA 


